File Handling Vulnerability in Firefox for Linux Distributions
CVE-2023-29541
8.8HIGH
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 2 June 2023
What is CVE-2023-29541?
A vulnerability in Firefox allows for improper handling of downloads of files with the .desktop extension, potentially enabling attackers to execute arbitrary commands. This issue specifically impacts users operating Firefox on certain Linux distributions, while other operating systems remain unaffected. Mozilla has identified affected versions, which include Firefox below version 112, Focus for Android below version 112, and Thunderbird below version 102.10, among others. Security measures are recommended for users on the affected platforms.
Affected Version(s)
Firefox < 112
Firefox ESR < 102.10
Firefox for Android < 112