First published: Tue Nov 02 2021(Updated: )
The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <91.3 | 91.3 |
<94 | 94 | |
<91.3 | 91.3 | |
<91.3 | 91.3 | |
Mozilla Firefox | <94.0 | |
Mozilla Firefox ESR | <91.3.0 | |
Mozilla Thunderbird | <91.3.0 | |
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2021-38510.
The title of the vulnerability is 'The executable file warning was not presented when downloading .inetloc files which can run commands...'
The affected software includes Mozilla Firefox ESR version up to 91.3, Mozilla Firefox version up to 94, and Mozilla Thunderbird version up to 91.3.
The severity of CVE-2021-38510 is medium (severity value: 4).
To fix CVE-2021-38510, users should update their Mozilla Firefox ESR version to 91.3, Mozilla Firefox version to 94, or Mozilla Thunderbird version to 91.3.