Join the AMA (Ask Me Anything) with the Firefox leadership team to celebrate Firefox 20th anniversary and discuss Firefox’s future on Mozilla Connect. Mark your calendar on Thursday, November 14, 18:00 - 20:00 UTC!

Fungovanie tejto stránky je z dôvodu údržby dočasne obmedzené. Ak článok nevyrieši váš problém a chcete položiť otázku, napíšte našej komunite podpory na Twitter @FirefoxSupport alebo Reddit /r/firefox.

Vyhľadajte odpoveď

Vyhnite sa podvodom s podporou. Nikdy vás nebudeme žiadať, aby ste zavolali alebo poslali SMS na telefónne číslo alebo zdieľali osobné informácie. Nahláste prosím podozrivú aktivitu použitím voľby “Nahlásiť zneužitie”.

Ďalšie informácie

Affected Firefox ESR versions for CVE-2023-3600

  • 5 odpovedí
  • 0 má tento problém
  • 1 zobrazenie
  • Posledná odpoveď od zeroknight

more options

We're currently using Firefox ESR 102.x and our VA software is reporting vulnerability issues with CVE-2023-3600 with says:

During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1.

Based on the scan report, my understanding is that this ONLY applies to ESR Builds of 115.x and not with ESR 102.x release.

does it mean that this CVE also affects our 102.x version?

Thanks!

We're currently using Firefox ESR 102.x and our VA software is reporting vulnerability issues with CVE-2023-3600 with says: During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1. Based on the scan report, my understanding is that this ONLY applies to ESR Builds of 115.x and not with ESR 102.x release. does it mean that this CVE also affects our 102.x version? Thanks!

Všetky odpovede (5)

more options

https://www.mozilla.org/security/advisories/mfsa2023-26/ CVE-2023-3600: Use-after-free in workers Fixed in Firefox 115.0.2 Firefox ESR 115.0.2

Firefox 115.0.2 is a older Fx 115 ESR version as there has since been 115.0.3, 115.1.0, 115.2.0 https://www.mozilla.org/firefox/releases/

Firefox 102 ESR was based on the Firefox 102.0 Release. Note the Fx 102.15.0 ESR was the last major update for this old ESR branch though there may be minor updates for security and or stability fixes if warranted, though it is considered EOL. Firefox 117.0 and 115.2.0 ESR are the current versions.

Security Advisories for Firefox https://www.mozilla.org/security/known-vulnerabilities/firefox/

Security Advisories for Firefox ESR https://www.mozilla.org/security/known-vulnerabilities/firefox-esr/

Upravil(a) James dňa

more options

So does this mean that 102 is different app/build from 115 and 102 is not affected by this CVE??

Thanks!

more options

Perhaps not by this one however the old Fx 102 ESR branch is EOL now with Firefox 117.0 and 1152.0 ESR the current versions.

Its possible the old EOL Fx 102 ESR branch is currently vulnerable to some things that has since been fixed in newer versions.

more options

James, Thanks for your response.

Can you help to get a proof that 102.x is not impacted by this CVE or at least a confirmation from Firefox. thanks!

more options

The code modified in the fix appears to have been added in 113 and does not exist in 102esr.