CVE-2023-29548: Medium severity thunderbird vulnerability
Published Apr 11, 2023
·Updated
A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result.
Affected Software
15 affected componentsFixes available
debian/firefox
131.0-1
debian/firefox-esr
115.14.0esr-1~deb11u1128.3.0esr-1~deb11u2115.14.0esr-1~deb12u1128.3.0esr-1~deb12u1115.15.0esr-1128.3.0esr-2
debian/thunderbird
1:115.12.0-1~deb11u11:115.15.0-1~deb11u11:115.12.0-1~deb12u11:115.15.0-1~deb12u11:128.2.0esr-11:128.3.0esr-1
Mozilla Thunderbird<102.10
102.10
Mozilla Firefox<112.0
Mozilla Firefox Android<112.0
Mozilla Firefox ESR<102.10
Mozilla Focus Android<112.0
Mozilla Thunderbird<102.10
Mozilla Firefox ESR<102.10
102.10
Mozilla Firefox<112
112
All of the following
Mozilla Firefox=112
Google Android
All of the following
Mozilla Focus=112
Google Android
Event History
Apr 11, 2023
CVE Published
12:00 AM
Jun 2, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
05:15 PM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:18 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·04:14 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:14 AM
DescriptionAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-29531
- CVE-2023-29532
- CVE-2023-29533
- CVE-2023-1999
- CVE-2023-29535
- CVE-2023-29536
- CVE-2023-0547
- CVE-2023-29479
- CVE-2023-29539
- CVE-2023-29541
- CVE-2023-29542
- CVE-2023-29545
- CVE-2023-1945
- CVE-2023-29548
- CVE-2023-29550
- CVE-2023-29534
- CVE-2023-29537
- CVE-2023-29538
- CVE-2023-29540
- CVE-2023-29543
- CVE-2023-29544
- CVE-2023-29546
- CVE-2023-29547
- CVE-2023-29549
- CVE-2023-29551
Frequently Asked Questions
1
What is CVE-2023-29548?
CVE-2023-29548 is a vulnerability in the ARM64 Ion compiler in Firefox, Focus for Android, Firefox ESR, and Thunderbird.
2
Which software is affected by CVE-2023-29548?
Firefox (<112), Focus for Android (<112), Firefox ESR (<102.10), and Thunderbird (<102.10) are affected by CVE-2023-29548.
3
What is the severity of CVE-2023-29548?
CVE-2023-29548 has a severity level of low.
4
How does CVE-2023-29548 impact the affected software?
CVE-2023-29548 results in a wrong optimization result due to a wrong lowering instruction in the ARM64 Ion compiler.
5
Is there a fix available for CVE-2023-29548?
Yes, a fix for CVE-2023-29548 is available. Please refer to the vendor's advisory for more information.