CVE-2023-29542
published 2023-06-19CVE-2023-29542: A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.94%
57.0th percentile
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code.
*This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 112.0 | 112.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 112 | 112 |
| mozilla | firefox_esr | < 102.10 | 102.10 |
| mozilla | firefox_esr | >= unspecified < 102.10 | 102.10 |
| mozilla | thunderbird | < 102.10 | 102.10 |
| mozilla | thunderbird | >= unspecified < 102.10 | 102.10 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Bypass of file download extension restrictions
vendor_redhat·2023-04-11·CVSS 9.8
CVE-2023-29542 [CRITICAL] CWE-434 Mozilla: Bypass of file download extension restrictions
Mozilla: Bypass of file download extension restrictions
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code.
*This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
The Mozilla Foundation Security Advisory describes this flaw as:
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code.
*This bug only affe
Debian
CVE-2023-29542: firefox - A newline in a filename could have been used to bypass the file extension securi...
vendor_debian·2023·CVSS 9.8
CVE-2023-29542 [CRITICAL] CVE-2023-29542: firefox - A newline in a filename could have been used to bypass the file extension securi...
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2023-15: CVE-2023-29542
vendor_mozilla·CVSS 9.8
CVE-2023-29542 [CRITICAL] Mozilla Foundation Security Advisory 2023-15: CVE-2023-29542
Mozilla Foundation Security Advisory 2023-15
CVE: CVE-2023-29542
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 102.10
Mozilla
Mozilla Foundation Security Advisory 2023-13: CVE-2023-29542
vendor_mozilla·CVSS 9.8
CVE-2023-29542 [CRITICAL] Mozilla Foundation Security Advisory 2023-13: CVE-2023-29542
Mozilla Foundation Security Advisory 2023-13
CVE: CVE-2023-29542
Product: Firefox, Firefox for Android, Focus for Android
Impact: high
Fixed in: Firefox 112
Firefox for Android 112
Focus for Android 112
Mozilla
Mozilla Foundation Security Advisory 2023-14: CVE-2023-29542
vendor_mozilla·CVSS 9.8
CVE-2023-29542 [CRITICAL] Mozilla Foundation Security Advisory 2023-14: CVE-2023-29542
Mozilla Foundation Security Advisory 2023-14
CVE: CVE-2023-29542
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 102.10
GHSA
GHSA-pc79-pjx7-pq9h: A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as
ghsa_unreviewed·2023-06-19
CVE-2023-29542 [CRITICAL] GHSA-pc79-pjx7-pq9h: A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code.
*This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
OSV
CVE-2023-29542: A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as
osv·2023-06-19·CVSS 9.8
CVE-2023-29542 [CRITICAL] CVE-2023-29542: A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
No detection rules found.
No public exploits indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1810793https://bugzilla.mozilla.org/show_bug.cgi?id=1815062https://www.mozilla.org/security/advisories/mfsa2023-13/https://www.mozilla.org/security/advisories/mfsa2023-14/https://www.mozilla.org/security/advisories/mfsa2023-15/https://bugzilla.mozilla.org/show_bug.cgi?id=1810793https://bugzilla.mozilla.org/show_bug.cgi?id=1815062https://www.mozilla.org/security/advisories/mfsa2023-13/https://www.mozilla.org/security/advisories/mfsa2023-14/https://www.mozilla.org/security/advisories/mfsa2023-15/
2023-06-19
Published