CVE-2025-1932: Inconsistent comparator in XSLT sorting led to out-of-bounds access
Published Mar 4, 2025
·Updated
An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later.
Affected Software
14 affected componentsFixes available
debian/firefox
136.0-1
debian/firefox-esr<=115.14.0esr-1~deb11u1, <=128.5.0esr-1~deb12u1
128.8.0esr-1~deb11u1128.8.0esr-1~deb12u1128.8.0esr-1
debian/thunderbird<=1:115.12.0-1~deb11u1, <=1:128.5.0esr-1~deb12u1, <=1:128.7.0esr-1
1:128.8.0esr-1~deb11u11:128.8.0esr-1~deb12u11:128.8.0esr-1
Mozilla Firefox<136
136
Mozilla Firefox ESR<128.8
128.8
Mozilla Thunderbird<136
136
Mozilla Thunderbird<128.8
128.8
Mozilla Firefox<136
Mozilla Firefox ESR<128.8
Mozilla xslt/txNodeSorter>=122
Mozilla Firefox<128.8.0
Mozilla Firefox<136.0
Mozilla Thunderbird>=]<128.8.0
Mozilla Thunderbird>=129.0<136.0
Event History
Mar 4, 2025
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
Description
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
Affected Software
Mar 10, 2025
Data Sourced
via Ubuntu·04:52 PM
RemedyDescriptionSeverityAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-1932?
CVE-2025-1932 has the potential for high severity due to the possibility of out-of-bounds access.
2
How do I fix CVE-2025-1932?
To fix CVE-2025-1932, upgrade to Firefox versions 137 or later, or Firefox ESR versions 129 or later.
3
Which versions are affected by CVE-2025-1932?
CVE-2025-1932 affects Firefox versions 122 to 136 and Firefox ESR versions 122 to 128.8.
4
What does CVE-2025-1932 affect specifically?
CVE-2025-1932 specifically affects the xslt/txNodeSorter component within the affected versions.
5
Is CVE-2025-1932 exploitable?
Yes, CVE-2025-1932 is potentially exploitable due to inconsistent comparator leading to out-of-bounds access.