CVE-2023-29541
published 2023-06-02CVE-2023-29541: Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. *This bug only affects…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.74%
50.7th percentile
Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. *This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 112.0-1 (sid) | firefox 112.0-1 (sid) |
| debian | firefox-esr | < firefox 112.0-1 (sid) | firefox 112.0-1 (sid) |
| debian | thunderbird | < firefox 112.0-1 (sid) | firefox 112.0-1 (sid) |
| mozilla | firefox | < 112.0 | 112.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 112.0.1+build1-0ubuntu0.18.04.1 | 112.0.1+build1-0ubuntu0.18.04.1 |
| mozilla | firefox | >= 0 < 112.0+build2-0ubuntu0.18.04.1 | 112.0+build2-0ubuntu0.18.04.1 |
| mozilla | firefox | >= 0 < 112.0.2+build1-0ubuntu0.18.04.1 | 112.0.2+build1-0ubuntu0.18.04.1 |
| mozilla | firefox | >= 0 < 112.0.1+build1-0ubuntu0.20.04.1 | 112.0.1+build1-0ubuntu0.20.04.1 |
| mozilla | firefox | >= 0 < 112.0+build2-0ubuntu0.20.04.1 | 112.0+build2-0ubuntu0.20.04.1 |
| mozilla | firefox | >= 0 < 112.0.2+build1-0ubuntu0.20.04.1 | 112.0.2+build1-0ubuntu0.20.04.1 |
| mozilla | firefox | >= unspecified < 112 | 112 |
| mozilla | firefox_esr | < 102.10 | 102.10 |
| mozilla | firefox_esr | >= unspecified < 102.10 | 102.10 |
| mozilla | firefox_for_android | >= unspecified < 112 | 112 |
| mozilla | focus | < 112.0 | 112.0 |
| mozilla | focus_for_android | >= unspecified < 112 | 112 |
| mozilla | thunderbird | < 102.10 | 102.10 |
| mozilla | thunderbird | >= 0 < 1:102.10.0-1~deb11u1 | 1:102.10.0-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0-1 | 1:102.10.0-1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0-1 | 1:102.10.0-1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0-1 | 1:102.10.0-1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0+build2-0ubuntu0.18.04.1 | 1:102.10.0+build2-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0+build2-0ubuntu0.20.04.1 | 1:102.10.0+build2-0ubuntu0.20.04.1 |
| mozilla | thunderbird | >= 0 < 1:102.10.0+build2-0ubuntu0.22.04.1 | 1:102.10.0+build2-0ubuntu0.22.04.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox regressions
vendor_ubuntu·2023-04-26·CVSS 4.3
[MEDIUM] Firefox regressions
Title: Firefox regressions
Summary: USN-6010-2 caused some minor regressions in Firefox.
USN-6010-1 fixed vulnerabilities and USN-6010-2 fixed minor regressions in
Firefox. The update introduced several minor regressions. This update fixes
the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-29537,
CVE-2023-29540, CVE-2023-29543, CVE-2023-29544, CVE-2023-29547,
CVE-2023-29548, CVE-2023-29549, CVE-2023-29550, CVE-2023-29551)
Irvan Kurniawan discovered that Firefox did not properly manage fulls
Ubuntu
Firefox regressions
vendor_ubuntu·2023-04-18·CVSS 4.3
[MEDIUM] Firefox regressions
Title: Firefox regressions
Summary: USN-6010-1 caused some minor regressions in Firefox.
USN-6010-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-29537,
CVE-2023-29540, CVE-2023-29543, CVE-2023-29544, CVE-2023-29547,
CVE-2023-29548, CVE-2023-29549, CVE-2023-29550, CVE-2023-29551)
Irvan Kurniawan discovered that Firefox did not properly manage fullscreen
notifications using a combination
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2023-04-13·CVSS 6.5
CVE-2023-29535 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-1945, CVE-2023-29548,
CVE-2023-29550)
Paul Menzel discovered that Thunderbird did not properly validate OCSP
revocation status of recipient certificates when sending S/Mime encrypted
email. An attacker could potentially exploits this issue to perform
spoofing attack. (CVE-2023-0547)
Ribose RNP Team discovered that Thunderbird did not properly manage memory
when pa
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2023-04-12·CVSS 4.3
CVE-2023-29540 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-29537,
CVE-2023-29540, CVE-2023-29543, CVE-2023-29544, CVE-2023-29547,
CVE-2023-29548, CVE-2023-29549, CVE-2023-29550, CVE-2023-29551)
Irvan Kurniawan discovered that Firefox did not properly manage fullscreen
notifications using a combination of window.open, fullscreen requests,
window.name assignments, and setInterval calls. An attacker could
potentially exploit this issue to perform spoofing attacks. (CVE-2023-29533)
Lukas Bernh
Red Hat
Mozilla: Files with malicious extensions could have been downloaded unsafely on Linux
vendor_redhat·2023-04-11·CVSS 8.8
CVE-2023-29541 [HIGH] CWE-434 Mozilla: Files with malicious extensions could have been downloaded unsafely on Linux
Mozilla: Files with malicious extensions could have been downloaded unsafely on Linux
Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. *This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
The Mozilla Foundation Security Advisory describes this flaw as:
Firefox did not properly handle downloads of files ending in `.desktop`, which can be interpreted to run attacker-controlled commands.
*This bug only affects Firefox for Linux on certain Distrib
Debian
CVE-2023-29541: firefox - Firefox did not properly handle downloads of files ending in <code>.desktop</cod...
vendor_debian·2023·CVSS 8.8
CVE-2023-29541 [HIGH] CVE-2023-29541: firefox - Firefox did not properly handle downloads of files ending in <code>.desktop</cod...
Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. *This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
Scope: local
sid: resolved (fixed in 112.0-1)
Mozilla
Mozilla Foundation Security Advisory 2023-14: CVE-2023-29541
vendor_mozilla·CVSS 8.8
CVE-2023-29541 [HIGH] Mozilla Foundation Security Advisory 2023-14: CVE-2023-29541
Mozilla Foundation Security Advisory 2023-14
CVE: CVE-2023-29541
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 102.10
Mozilla
Mozilla Foundation Security Advisory 2023-13: CVE-2023-29541
vendor_mozilla·CVSS 8.8
CVE-2023-29541 [HIGH] Mozilla Foundation Security Advisory 2023-13: CVE-2023-29541
Mozilla Foundation Security Advisory 2023-13
CVE: CVE-2023-29541
Product: Firefox, Firefox for Android, Focus for Android
Impact: high
Fixed in: Firefox 112
Firefox for Android 112
Focus for Android 112
Mozilla
Mozilla Foundation Security Advisory 2023-15: CVE-2023-29541
vendor_mozilla·CVSS 8.8
CVE-2023-29541 [HIGH] Mozilla Foundation Security Advisory 2023-15: CVE-2023-29541
Mozilla Foundation Security Advisory 2023-15
CVE: CVE-2023-29541
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 102.10
OSV
CVE-2023-29541: Firefox did not properly handle downloads of files ending in
osv·2023-06-02·CVSS 8.8
CVE-2023-29541 [HIGH] CVE-2023-29541: Firefox did not properly handle downloads of files ending in
Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. *This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
GHSA
GHSA-wm65-g4q2-jh7c: Firefox did not properly handle downloads of files ending in
ghsa_unreviewed·2023-06-02
CVE-2023-29541 CWE-116 GHSA-wm65-g4q2-jh7c: Firefox did not properly handle downloads of files ending in
Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. *This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
OSV
firefox regressions
osv·2023-04-26·CVSS 4.3
[MEDIUM] firefox regressions
firefox regressions
USN-6010-1 fixed vulnerabilities and USN-6010-2 fixed minor regressions in
Firefox. The update introduced several minor regressions. This update fixes
the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-29537,
CVE-2023-29540, CVE-2023-29543, CVE-2023-29544, CVE-2023-29547,
CVE-2023-29548, CVE-2023-29549, CVE-2023-29550, CVE-2023-29551)
Irvan Kurniawan discovered that Firefox did not properly manage fullscreen
notifications using a combination of window.open, fullscreen req
OSV
firefox regressions
osv·2023-04-18·CVSS 4.3
CVE-2023-29537 [MEDIUM] firefox regressions
firefox regressions
USN-6010-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-29537,
CVE-2023-29540, CVE-2023-29543, CVE-2023-29544, CVE-2023-29547,
CVE-2023-29548, CVE-2023-29549, CVE-2023-29550, CVE-2023-29551)
Irvan Kurniawan discovered that Firefox did not properly manage fullscreen
notifications using a combination of window.open, fullscreen requests,
window.name assignments, and set
OSV
thunderbird vulnerabilities
osv·2023-04-13·CVSS 6.5
CVE-2023-1945 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code. (CVE-2023-1945, CVE-2023-29548,
CVE-2023-29550)
Paul Menzel discovered that Thunderbird did not properly validate OCSP
revocation status of recipient certificates when sending S/Mime encrypted
email. An attacker could potentially exploits this issue to perform
spoofing attack. (CVE-2023-0547)
Ribose RNP Team discovered that Thunderbird did not properly manage memory
when parsing certain OpenPGP messages. An attacker could potentially
exploi
OSV
firefox vulnerabilities
osv·2023-04-12·CVSS 4.3
CVE-2023-29537 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-29537,
CVE-2023-29540, CVE-2023-29543, CVE-2023-29544, CVE-2023-29547,
CVE-2023-29548, CVE-2023-29549, CVE-2023-29550, CVE-2023-29551)
Irvan Kurniawan discovered that Firefox did not properly manage fullscreen
notifications using a combination of window.open, fullscreen requests,
window.name assignments, and setInterval calls. An attacker could
potentially exploit this issue to perform spoofing attacks. (CVE-2023-29533)
Lukas Bernhard discovered that Firefox did not properly manage memory
when
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1810191https://www.mozilla.org/security/advisories/mfsa2023-13/https://www.mozilla.org/security/advisories/mfsa2023-14/https://www.mozilla.org/security/advisories/mfsa2023-15/https://bugzilla.mozilla.org/show_bug.cgi?id=1810191https://www.mozilla.org/security/advisories/mfsa2023-13/https://www.mozilla.org/security/advisories/mfsa2023-14/https://www.mozilla.org/security/advisories/mfsa2023-15/
2023-06-02
Published