为提升您的使用体验,本站正在维护,部分功能暂时无法使用。如果本站文章无法解决您的问题,您想要向社区提问的话,请到 Twitter 上的 @FirefoxSupport 或 Reddit 上的 /r/firefox 提问,我们的支持社区将会很快回复您的疑问。

搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

详细了解

CVE-2023-3600

  • 5 个回答
  • 0 人有此问题
  • 1 次查看
  • 最后回复者为 goku

more options

Hi,

regarding vulnerability CVE-2023-3600 when I check advisories it says that version below 115.0.2 ESR are affected. Does that mean that only 115.x versions are affected or all versions are affected like 102.x ?

Regards

Hi, regarding vulnerability CVE-2023-3600 when I check advisories it says that version below 115.0.2 ESR are affected. Does that mean that only 115.x versions are affected or all versions are affected like 102.x ? Regards

所有回复 (5)

more options

Firefox ESR versions https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/

Firefox Release https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox/

https://www.mozilla.org/en-US/security/advisories/mfsa2023-26/ Says CVE-2023-3600: Use-after-free in workers was fixed in Firefox 115.0.2 Firefox ESR 115.0.2. They would have ported the fix to 102 ESR if it was found vulnerable to this also.

The old Fx 102 ESR channel is coming to an end as 102.15.0 ESR will be the last major update for it.

由James于修改

more options

ok. thanks. So you are saying that this vulnerability exists also in v102, not just in v115 ?

more options

is firefox esr 102 affected by CVE-2023-3600?

more options

The code that was changed doesn't appear to be present in 102 ESR if I search the HG website, so the 102 ESR branch is likely not affected.

more options

thanks cor-el, can you pls share the link? thanks