CVE-2023-6857 Information

Description

When resolving a symlink a race may occur where the buffer passed to readlink may actually be smaller than necessary. This bug only affects Firefox on Unix-based operating systems (Android Linux MacOS). Windows is unaffected. This vulnerability affects Firefox ESR < 115.6 Thunderbird < 115.6 and Firefox < 121.

Reference

https://bugzilla.mozilla.org/show_bug.cgi?id=1796023 https://www.mozilla.org/security/advisories/mfsa2023-54/ https://www.mozilla.org/security/advisories/mfsa2023-55/ https://www.mozilla.org/security/advisories/mfsa2023-56/ https://www.debian.org/security/2023/dsa-5581

Share on: