CVE-2023-4582

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
11/09/2023
Last modified:
18/12/2025

Description

Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when allocating too much private shader memory on mac OS. <br /> *This bug only affects Firefox on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 117.0 (excluding)
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* 115.2 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 115.2 (excluding)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*