CVE-2019-7317

Description

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.565

Associated Vulnerability

VulnerabilityOS Platform
Update Mozilla Firefox (67.0) fixes multiple vulnerabilitesWindows
Update Mozilla Firefox (x64) (67.0) fixes multiple vulnerabilitesWindows
Update Mozilla Firefox ESR (60.7.0) fixes multiple vulnerabilitesWindows
Update Mozilla Firefox ESR (x64) (60.7.0) fixes multiple vulnerabilitesWindows
Update Mozilla Thunderbird (60.7.0) fixes multiple vulnerabilitesWindows
Multiple vulnerabilities affected in Oracle Java SE 8u311Windows
Multiple vulnerabilities affected in Oracle Java SE 8u311 (x64)Windows
Multiple vulnerabilities affected in Oracle Java SE Developement -Kit 8u311Windows
Multiple vulnerabilities affected in Oracle Java SE Developement Kit 8u311 (x64)Windows
Multiple vulnerabilities are affected in Java SE Development Kit 11.0.3Windows
Multiple vulnerabilities are affected in Java SE Development Kit 1.7.0.2210Windows
Multiple vulnerabilities are affected in Java SE Development Kit 8.0.2120Windows
Multiple vulnerabilities are affected in Java SE Development Kit 12.0.1Windows
Multiple vulnerabilities are affected in Java SE Development Kit (x64) Java SE Development Kit 8 Update 211 (64-bit)Windows
Multiple vulnerabilities are affected in Java SE Development Kit Java SE Development Kit 8 Update 211 (64-bit)Windows
Multiple vulnerabilities are affected in Java SE Development Kit (x64) 11.0.3Windows
Multiple vulnerabilities are affected in Java SE Development Kit (x64) 1.7.0.2210Windows
Multiple vulnerabilities are affected in Java SE Development Kit (x64) 8.0.2120Windows
Multiple vulnerabilities are affected in Java SE Development Kit (x64) 12.0.1Windows
Multiple vulnerabilities are affected in Java SE Development Kit (x64) 8.0.2110Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 11 (ML) (EXE) (11.2.3.53593)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 11 (ML) (MSI) (11.2.3.53593)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 11 (EXE) (11.2.3.53593)Windows
Multiple vulnerabilities are fixed in Foxit PDF Editor 11 (MSI) (11.2.3.53593)Windows
Multiple vulnerabilities are fixed in Azul Zulu JDK 7 7.31Windows
Multiple vulnerabilities are fixed in Azul Zulu JDK 7 (x64) 7.31Windows
Multiple vulnerabilities are fixed in Azul Zulu JDK 8 (MSI) 8.40Windows
Multiple vulnerabilities are fixed in Azul Zulu JDK 8 (MSI) (x64) 8.40Windows
Multiple vulnerabilities are fixed in Azul Zulu JDK 11 (MSI) (x64) 11.33Windows
Vulnerabilities CVE-2019-7317,CVE-2021-3450 are affected in MySQL Workbench Enterprise Edition 8.0.23Windows
Vulnerabilities CVE-2019-7317,CVE-2021-3450 are affected in MySQL Workbench CE (x64) 8.0.23Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.6Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 2.3Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 2.3Windows
Vulnerabilities CVE-2019-7317 are affected in Mozilla Thunderbird 2.3Windows
Vulnerabilities CVE-2019-7317 are affected in Netapp Active Iq Unified Manager 9.5Windows
Vulnerabilities CVE-2019-7317 are affected in Netapp Active Iq Unified Manager 9.6Windows
Vulnerabilities CVE-2019-7317 are affected in Netapp Oncommand Insight 7.3.8Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Workflow Automation 5.0Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 9.6Windows
Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (67.0.1)Mac
Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (67.0.2)Mac
Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (67.0.3)Mac
Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (67.0.4)Mac
Multiple vulnerabilities are fixed in Update for Mozilla Thunderbird For Mac (60.7.0)Mac
Multiple vulnerabilities are fixed in Update for Mozilla Thunderbird For Mac (60.7.2)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac 60.7Mac
firefox-esr security update(DSA-4411-1) firefox-esr_60.7.0esr-1~deb9u1_i386.debLinux
firefox-esr security update(DSA-4411-1) firefox-esr_60.7.0esr-1~deb9u1_amd64.debLinux
thunderbird security update(DSA-4420-1) thunderbird_60.7.0-1~deb9u1_i386.debLinux
firefox-esr security update(DSA-4448-1) firefox-esr_60.7.0esr-1~deb9u1_i386.debLinux
firefox-esr security update(DSA-4448-1) firefox-esr_60.7.0esr-1~deb9u1_amd64.debLinux
thunderbird security update(DSA-4451-1) thunderbird_60.7.0-1~deb9u1_i386.debLinux
thunderbird security update(DSA-4451-1) thunderbird_60.7.0-1~deb9u1_amd64.debLinux
Open Source Java implementation (USN-4080-1) openjdk-8-jdk_8u222-b10-1ubuntu1~16.04.1_i386.debLinux
Open Source Java implementation (USN-4080-1) openjdk-8-jdk_8u222-b10-1ubuntu1~16.04.1_amd64.debLinux
Open Source Java implementation (USN-4080-1) openjdk-8-jre_8u222-b10-1ubuntu1~16.04.1_i386.debLinux
Open Source Java implementation (USN-4080-1) openjdk-8-jre_8u222-b10-1ubuntu1~16.04.1_amd64.debLinux
Open Source Java implementation (USN-4080-1) openjdk-8-jre-zero_8u222-b10-1ubuntu1~16.04.1_i386.debLinux
Open Source Java implementation (USN-4080-1) openjdk-8-jre-zero_8u222-b10-1ubuntu1~16.04.1_amd64.debLinux
Open Source Java implementation (USN-4080-1) openjdk-8-jre-jamvm_8u222-b10-1ubuntu1~16.04.1_i386.debLinux
Open Source Java implementation (USN-4080-1) openjdk-8-jre-jamvm_8u222-b10-1ubuntu1~16.04.1_amd64.debLinux
Open Source Java implementation (USN-4080-1) openjdk-8-jdk-headless_8u222-b10-1ubuntu1~16.04.1_i386.debLinux
Open Source Java implementation (USN-4080-1) openjdk-8-jdk-headless_8u222-b10-1ubuntu1~16.04.1_amd64.debLinux
Open Source Java implementation (USN-4080-1) openjdk-8-jre-headless_8u222-b10-1ubuntu1~16.04.1_i386.debLinux
Open Source Java implementation (USN-4080-1) openjdk-8-jre-headless_8u222-b10-1ubuntu1~16.04.1_amd64.debLinux
SUSE-SU-2019:2336-1(SUSE Linux Enterprise Server 12-SP4 ) java-1_7_1-ibm-1.7.1_sr4.50-38.41.1.x86_64.rpmLinux
SUSE-SU-2019:2336-1(SUSE Linux Enterprise Server 12-SP4 ) java-1_7_1-ibm-alsa-1.7.1_sr4.50-38.41.1.x86_64.rpmLinux
SUSE-SU-2019:2336-1(SUSE Linux Enterprise Server 12-SP4 ) java-1_7_1-ibm-jdbc-1.7.1_sr4.50-38.41.1.x86_64.rpmLinux
SUSE-SU-2019:2336-1(SUSE Linux Enterprise Server 12-SP4 ) java-1_7_1-ibm-plugin-1.7.1_sr4.50-38.41.1.x86_64.rpmLinux
SUSE-SU-2019:2371-1(SUSE Linux Enterprise Server 12-SP4 ) java-1_8_0-ibm-1.8.0_sr5.40-30.54.1.x86_64.rpmLinux
SUSE-SU-2019:2371-1(SUSE Linux Enterprise Server 12-SP4 ) java-1_8_0-ibm-alsa-1.8.0_sr5.40-30.54.1.x86_64.rpmLinux
SUSE-SU-2019:2371-1(SUSE Linux Enterprise Server 12-SP4 ) java-1_8_0-ibm-plugin-1.8.0_sr5.40-30.54.1.x86_64.rpmLinux
(RHSA-2019:2494) java-1.7.1-ibm security update java-1.7.1-ibm-1.7.1.4.50-1jpp.1.el6_10.i686.rpmLinux
(RHSA-2019:2494) java-1.7.1-ibm security update java-1.7.1-ibm-1.7.1.4.50-1jpp.1.el6_10.x86_64.rpmLinux
(RHSA-2019:2494) java-1.7.1-ibm security update java-1.7.1-ibm-demo-1.7.1.4.50-1jpp.1.el6_10.i686.rpmLinux
(RHSA-2019:2494) java-1.7.1-ibm security update java-1.7.1-ibm-demo-1.7.1.4.50-1jpp.1.el6_10.x86_64.rpmLinux
(RHSA-2019:2494) java-1.7.1-ibm security update java-1.7.1-ibm-devel-1.7.1.4.50-1jpp.1.el6_10.i686.rpmLinux
(RHSA-2019:2494) java-1.7.1-ibm security update java-1.7.1-ibm-devel-1.7.1.4.50-1jpp.1.el6_10.x86_64.rpmLinux
(RHSA-2019:2494) java-1.7.1-ibm security update java-1.7.1-ibm-jdbc-1.7.1.4.50-1jpp.1.el6_10.i686.rpmLinux
(RHSA-2019:2494) java-1.7.1-ibm security update java-1.7.1-ibm-jdbc-1.7.1.4.50-1jpp.1.el6_10.x86_64.rpmLinux
(RHSA-2019:2494) java-1.7.1-ibm security update java-1.7.1-ibm-plugin-1.7.1.4.50-1jpp.1.el6_10.i686.rpmLinux
(RHSA-2019:2494) java-1.7.1-ibm security update java-1.7.1-ibm-plugin-1.7.1.4.50-1jpp.1.el6_10.x86_64.rpmLinux
(RHSA-2019:2494) java-1.7.1-ibm security update java-1.7.1-ibm-src-1.7.1.4.50-1jpp.1.el6_10.i686.rpmLinux
(RHSA-2019:2494) java-1.7.1-ibm security update java-1.7.1-ibm-src-1.7.1.4.50-1jpp.1.el6_10.x86_64.rpmLinux
(RHSA-2019:2495) java-1.7.1-ibm security update java-1.7.1-ibm-1.7.1.4.50-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2019:2495) java-1.7.1-ibm security update java-1.7.1-ibm-demo-1.7.1.4.50-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2019:2495) java-1.7.1-ibm security update java-1.7.1-ibm-devel-1.7.1.4.50-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2019:2495) java-1.7.1-ibm security update java-1.7.1-ibm-jdbc-1.7.1.4.50-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2019:2495) java-1.7.1-ibm security update java-1.7.1-ibm-plugin-1.7.1.4.50-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2019:2495) java-1.7.1-ibm security update java-1.7.1-ibm-src-1.7.1.4.50-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2019:2585) java-1.8.0-ibm security update java-1.8.0-ibm-1.8.0.5.40-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2019:2585) java-1.8.0-ibm security update java-1.8.0-ibm-demo-1.8.0.5.40-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2019:2585) java-1.8.0-ibm security update java-1.8.0-ibm-devel-1.8.0.5.40-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2019:2585) java-1.8.0-ibm security update java-1.8.0-ibm-jdbc-1.8.0.5.40-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2019:2585) java-1.8.0-ibm security update java-1.8.0-ibm-plugin-1.8.0.5.40-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2019:2585) java-1.8.0-ibm security update java-1.8.0-ibm-src-1.8.0.5.40-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2019:2590) java-1.8.0-ibm security update java-1.8.0-ibm-1.8.0.5.40-3.el8_0.x86_64.rpmLinux
(RHSA-2019:2590) java-1.8.0-ibm security update java-1.8.0-ibm-demo-1.8.0.5.40-3.el8_0.x86_64.rpmLinux
(RHSA-2019:2590) java-1.8.0-ibm security update java-1.8.0-ibm-devel-1.8.0.5.40-3.el8_0.x86_64.rpmLinux
(RHSA-2019:2590) java-1.8.0-ibm security update java-1.8.0-ibm-headless-1.8.0.5.40-3.el8_0.x86_64.rpmLinux
(RHSA-2019:2590) java-1.8.0-ibm security update java-1.8.0-ibm-jdbc-1.8.0.5.40-3.el8_0.x86_64.rpmLinux
(RHSA-2019:2590) java-1.8.0-ibm security update java-1.8.0-ibm-plugin-1.8.0.5.40-3.el8_0.x86_64.rpmLinux
(RHSA-2019:2590) java-1.8.0-ibm security update java-1.8.0-ibm-src-1.8.0.5.40-3.el8_0.x86_64.rpmLinux
(RHSA-2019:2590) java-1.8.0-ibm security update java-1.8.0-ibm-webstart-1.8.0.5.40-3.el8_0.x86_64.rpmLinux
(RHSA-2019:2592) java-1.8.0-ibm security update java-1.8.0-ibm-1.8.0.5.40-1jpp.1.el6_10.i686.rpmLinux
(RHSA-2019:2592) java-1.8.0-ibm security update java-1.8.0-ibm-1.8.0.5.40-1jpp.1.el6_10.x86_64.rpmLinux
(RHSA-2019:2592) java-1.8.0-ibm security update java-1.8.0-ibm-demo-1.8.0.5.40-1jpp.1.el6_10.i686.rpmLinux
(RHSA-2019:2592) java-1.8.0-ibm security update java-1.8.0-ibm-demo-1.8.0.5.40-1jpp.1.el6_10.x86_64.rpmLinux
(RHSA-2019:2592) java-1.8.0-ibm security update java-1.8.0-ibm-devel-1.8.0.5.40-1jpp.1.el6_10.i686.rpmLinux
(RHSA-2019:2592) java-1.8.0-ibm security update java-1.8.0-ibm-devel-1.8.0.5.40-1jpp.1.el6_10.x86_64.rpmLinux
(RHSA-2019:2592) java-1.8.0-ibm security update java-1.8.0-ibm-jdbc-1.8.0.5.40-1jpp.1.el6_10.i686.rpmLinux
(RHSA-2019:2592) java-1.8.0-ibm security update java-1.8.0-ibm-jdbc-1.8.0.5.40-1jpp.1.el6_10.x86_64.rpmLinux
(RHSA-2019:2592) java-1.8.0-ibm security update java-1.8.0-ibm-plugin-1.8.0.5.40-1jpp.1.el6_10.i686.rpmLinux
(RHSA-2019:2592) java-1.8.0-ibm security update java-1.8.0-ibm-plugin-1.8.0.5.40-1jpp.1.el6_10.x86_64.rpmLinux
(RHSA-2019:2592) java-1.8.0-ibm security update java-1.8.0-ibm-src-1.8.0.5.40-1jpp.1.el6_10.i686.rpmLinux
(RHSA-2019:2592) java-1.8.0-ibm security update java-1.8.0-ibm-src-1.8.0.5.40-1jpp.1.el6_10.x86_64.rpmLinux
SUSE-SU-2019:3060-1(SUSE Linux Enterprise Desktop 12-SP4 ) libpng16-16-1.6.8-15.5.2.x86_64.rpmLinux
SUSE-SU-2019:3060-1(SUSE Linux Enterprise Desktop 12-SP4 ) libpng16-16-32bit-1.6.8-15.5.2.x86_64.rpmLinux
SUSE-SU-2019:3060-1(SUSE Linux Enterprise Desktop 12-SP4 ) libpng16-16-debuginfo-1.6.8-15.5.2.x86_64.rpmLinux
SUSE-SU-2019:3060-1(SUSE Linux Enterprise Desktop 12-SP4 ) libpng16-16-debuginfo-32bit-1.6.8-15.5.2.x86_64.rpmLinux
SUSE-SU-2019:3060-1(SUSE Linux Enterprise Desktop 12-SP4 ) libpng16-debugsource-1.6.8-15.5.2.x86_64.rpmLinux
(RHSA-2019:1269) firefox security update firefox-60.7.0-1.el8_0.x86_64.rpmLinux
(RHSA-2019:1269) firefox security update firefox-debugsource-60.7.0-1.el8_0.x86_64.rpmLinux
(RHSA-2019:1308) thunderbird security update thunderbird-60.7.0-1.el8_0.x86_64.rpmLinux
(RHSA-2019:1308) thunderbird security update thunderbird-debugsource-60.7.0-1.el8_0.x86_64.rpmLinux
SUSE-SU-2019:2036-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-openjdk-1.8.0.222-27.35.2.x86_64.rpmLinux
SUSE-SU-2019:2036-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-openjdk-debuginfo-1.8.0.222-27.35.2.x86_64.rpmLinux
SUSE-SU-2019:2036-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-openjdk-debugsource-1.8.0.222-27.35.2.x86_64.rpmLinux
SUSE-SU-2019:2036-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-openjdk-demo-1.8.0.222-27.35.2.x86_64.rpmLinux
SUSE-SU-2019:2036-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-openjdk-demo-debuginfo-1.8.0.222-27.35.2.x86_64.rpmLinux
SUSE-SU-2019:2036-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-openjdk-devel-1.8.0.222-27.35.2.x86_64.rpmLinux
SUSE-SU-2019:2036-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-openjdk-devel-debuginfo-1.8.0.222-27.35.2.x86_64.rpmLinux
SUSE-SU-2019:2036-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-openjdk-headless-1.8.0.222-27.35.2.x86_64.rpmLinux
SUSE-SU-2019:2036-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-openjdk-headless-debuginfo-1.8.0.222-27.35.2.x86_64.rpmLinux
SUSE-SU-2019:2336-1(SUSE Linux Enterprise Server 12-SP5) java-1_7_1-ibm-1.7.1_sr4.50-38.41.1.x86_64_12_SP5.rpmLinux
SUSE-SU-2019:2336-1(SUSE Linux Enterprise Server 12-SP5) java-1_7_1-ibm-alsa-1.7.1_sr4.50-38.41.1.x86_64_12_SP5.rpmLinux
SUSE-SU-2019:2336-1(SUSE Linux Enterprise Server 12-SP5) java-1_7_1-ibm-jdbc-1.7.1_sr4.50-38.41.1.x86_64_12_SP5.rpmLinux
SUSE-SU-2019:2336-1(SUSE Linux Enterprise Server 12-SP5) java-1_7_1-ibm-plugin-1.7.1_sr4.50-38.41.1.x86_64_12_SP5.rpmLinux
SUSE-SU-2019:2371-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-ibm-1.8.0_sr5.40-30.54.1.x86_64_12_SP5.rpmLinux
SUSE-SU-2019:2371-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-ibm-alsa-1.8.0_sr5.40-30.54.1.x86_64_12_SP5.rpmLinux
SUSE-SU-2019:2371-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-ibm-plugin-1.8.0_sr5.40-30.54.1.x86_64_12_SP5.rpmLinux
SUSE-SU-2019:3060-1(SUSE Linux Enterprise Server 12-SP5 ) libpng16-16-1.6.8-15.5.2.x86_64_12_SP5.rpmLinux
SUSE-SU-2019:3060-1(SUSE Linux Enterprise Server 12-SP5 ) libpng16-16-32bit-1.6.8-15.5.2.x86_64_12_SP5.rpmLinux
SUSE-SU-2019:3060-1(SUSE Linux Enterprise Server 12-SP5 ) libpng16-16-debuginfo-1.6.8-15.5.2.x86_64_12_SP5.rpmLinux
SUSE-SU-2019:3060-1(SUSE Linux Enterprise Server 12-SP5 ) libpng16-16-debuginfo-32bit-1.6.8-15.5.2.x86_64_12_SP5.rpmLinux
SUSE-SU-2019:3060-1(SUSE Linux Enterprise Server 12-SP5 ) libpng16-debugsource-1.6.8-15.5.2.x86_64_12_SP5.rpmLinux
Use After Free Vulnerability (CVE-2019-7317)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-309861Mozilla Firefox (67.0)
PATCH-309862Mozilla Firefox (x64) (67.0)
PATCH-309865Mozilla Firefox ESR (60.7.0)
PATCH-309867Mozilla Firefox ESR (x64) (60.7.0)
PATCH-309864Mozilla Thunderbird (60.7.0)
PATCH-323264Java 8 Update 321 (8.0.3210.7) (JRE)
PATCH-323263Java 8 Update 321 (64-bit) (8.0.3210.7) (JRE)
PATCH-323267Java SE Development Kit 8 Update 321 (32-bit) (8.0.3210.7) (JDK)
PATCH-323266Java SE Development Kit 8 Update 321 (64-bit) (8.0.3210.7) (JDK)
PATCH-330243Java SE Development Kit 8 Update 371 (32-bit) (8.0.3710.11) (JDK)
PATCH-330242Java SE Development Kit 8 Update 371 (64-bit) (8.0.3710.11) (JDK)
PATCH-330242Java SE Development Kit 8 Update 371 (64-bit) (8.0.3710.11) (JDK)
PATCH-330913Foxit PDF Editor 11 (ML) (EXE) (11.2.6.53790)
PATCH-330914Foxit PDF Editor 11 (ML) (MSI) (11.2.6.53790)
PATCH-330912Foxit PDF Editor 11 (EXE) (11.2.6.53790)
PATCH-330915Foxit PDF Editor 11 (MSI) (11.2.6.53790)
PATCH-342222Azul Zulu JDK 8 (MSI) (8.82.0.21)
PATCH-342223Azul Zulu JDK 8 (MSI) (x64) (8.82.0.21)
PATCH-342218Azul Zulu JDK 11 (MSI) (x64) (11.76.21)
PATCH-347137MySQL Workbench CE (x64) (8.0.42)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-611353Mozilla Thunderbird For Mac (128.12.0)
PATCH-611353Mozilla Thunderbird For Mac (128.12.0)
PATCH-612783Mozilla Firefox For Mac (145.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234