When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
2023-12-19T14:15:07.377
2024-11-21T08:44:41.833
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 121.0 | Yes |
Application | mozilla | firefox_esr | < 115.6 | Yes |
Application | mozilla | thunderbird | < 115.6 | Yes |
Operating System | apple | macos | - | No |
Operating System | android | - | No | |
Operating System | linux | linux_kernel | - | No |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |
Operating System | debian | debian_linux | 12.0 | Yes |