AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding() and AppendEncodedCharacters() could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 115.9.0 |
| mozilla / thunderbird | - | 115.9.0 |
| mozilla / firefox | - | 124.0 |
| debian / debian_linux | 10.0 | 10.0.x |