Mozilla Firefox Security Updates 18 January 2023

Mozilla has released security updates to fix vulnerabilities in Firefox 109 and Firefox ESR 102.7.

The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, perform spoofing attacks, bypass security restrictions, execute arbitrary code and gain access to the affected products. Successful exploitation of these vulnerabilities may result in a complete compromise of vulnerable systems.

Sample of the addressed vulnerabilities:

1- Mozilla Firefox Safety Bugs Code Execution (CVE-2023-23605):

• CVSS: 8.8

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: None

• User Interaction: Required

• Consequences: Gain Access

2- Mozilla Firefox Information Disclosure (CVE-2023-23598):

• CVSS: 6.5

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: None

• User Interaction: Required

• Consequences: Obtain Information

Vulnerabilities
  • CVE-2023-23597
  • CVE-2023-23598
  • CVE-2023-23599
  • CVE-2023-23600
  • CVE-2023-23601
  • CVE-2023-23602
  • CVE-2023-23603
  • CVE-2023-23604
  • CVE-2023-23605
  • CVE-2023-23606
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Mozilla Firefox 109 Security Advisory

Mozilla Firefox ESR 102.7 Security Advisory

References