Mozilla: Zero-day vulnerabilities in Firefox browser and Thunderbird have been fixed, users are advised to update in a timely manner.
BlockBeats News, September 13th, Mozilla, the developer of the Firefox browser, released a security update on Tuesday to address a critical zero-day vulnerability in Firefox and Thunderbird that has been actively exploited in the wild. The issue has been resolved in Firefox 117.0.1, Firefox ESR 115.2.1, Firefox ESR 102.15.1, Thunderbird 102.15.1, and Thunderbird 115.2.2, and users are advised to upgrade promptly.
This vulnerability, identified as CVE-2023-4863, is a heap buffer overflow vulnerability in the WebP image format that could lead to arbitrary code execution when processing specially crafted images. According to the description from the National Vulnerability Database of the United States, this vulnerability may allow remote attackers to perform out-of-bounds memory writes by means of a specially crafted HTML page. (The Hacker News)