CVE-2023-29542

CVSS v3.1 9.8 (Critical)
98% Progress
EPSS 0.25 % (66th)
0.25% Progress
Affected Products 4
Advisories 9

A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code.

This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected. This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

Weaknesses
CWE-NVD-noinfo
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2023-06-19 11:15:09
(15 months ago)
Updated Date
2023-06-27 08:51:31
(14 months ago)

Affected Products

Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Mozilla Firefox prior 112.0 version cpe:2.3:a:mozilla:firefox < 112.0
OR  
  Running on/with
  Mozilla Firefox Esr prior 102.10 version cpe:2.3:a:mozilla:firefox_esr < 102.10
OR  
  Running on/with
  Mozilla Thunderbird prior 102.10 version cpe:2.3:a:mozilla:thunderbird < 102.10
OR  
  Running on/with
  Microsoft Windows cpe:2.3:o:microsoft:windows:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...