CVE-2023-6856 Vulnerability Details

  /     /     /  

CVE-2023-6856 Metadata Quick Info

CVE Published: 19/12/2023 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: mozilla | Vendor: Mozilla | Product: Firefox ESR
Status : PUBLISHED

CVE-2023-6856 Description

The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Heap-buffer-overflow affecting WebGL DrawElementsInstanced method with Mesa VM driver
Source: Mozilla

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).