CVE-2023-6866: High severity firefox vulnerability
Published Dec 19, 2023
·Updated
Last updated 24 July 2024
Other sources
TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect TypedArrays to always succeed.
— Mozilla
Affected Software
3 affected componentsFixes available
Mozilla Firefox<121
121
Mozilla Firefox<121.0
debian/firefox
138.0.1-1
Event History
Dec 19, 2023
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
DescriptionWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:29 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·04:19 AM
RemedyDescriptionSeverityAffected Software
Apr 4, 2025
Data Sourced
via Debian·04:33 AM
DescriptionAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2023-6866?
CVE-2023-6866 is considered a moderate severity vulnerability due to improper exception handling in TypedArrays.
2
How do I fix CVE-2023-6866?
To fix CVE-2023-6866, upgrade to the latest version of Firefox, specifically version 134.0.2-2 or later.
3
What software is affected by CVE-2023-6866?
CVE-2023-6866 affects Mozilla Firefox versions prior to 121.
4
What are the potential impacts of CVE-2023-6866?
CVE-2023-6866 could lead to abuse in other APIs that rely on TypedArrays functioning correctly.
5
Is CVE-2023-6866 present in Debian's Firefox package?
Yes, Debian's Firefox packages prior to version 134.0.2-2 may be vulnerable to CVE-2023-6866.