cbcvebase.
CVE-2023-29542
published 2023-06-19

CVE-2023-29542: A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with…

PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.94%
57.0th percentile
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianfirefox
debianfirefox-esr
debianthunderbird
mozillafirefox< 112.0112.0
mozillafirefox
mozillafirefox>= unspecified < 112112
mozillafirefox_esr< 102.10102.10
mozillafirefox_esr>= unspecified < 102.10102.10
mozillathunderbird< 102.10102.10
mozillathunderbird>= unspecified < 102.10102.10

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.