CVE-2023-29541: High severity Mozilla Thunderbird vulnerability
Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.
Other sources
Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
Thunderbird did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. This bug only affects Thunderbird for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 131.0-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 128.3.0esr-1~deb11u2Fixed in 115.14.0esr-1~deb12u1Fixed in 128.3.0esr-1~deb12u1Fixed in 115.15.0esr-1Fixed in 128.3.0esr-2 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:115.15.0-1~deb11u1Fixed in 1:115.12.0-1~deb12u1Fixed in 1:115.15.0-1~deb12u1Fixed in 1:128.2.0esr-1Fixed in 1:128.3.0esr-1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 102.10 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 102.10 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 112 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 112 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 102.10
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-29531
- CVE-2023-29532
- CVE-2023-29533
- CVE-2023-1999
- CVE-2023-29535
- CVE-2023-29536
- CVE-2023-0547
- CVE-2023-29479
- CVE-2023-29539
- CVE-2023-29541
- CVE-2023-29542
- CVE-2023-29545
- CVE-2023-1945
- CVE-2023-29548
- CVE-2023-29550
- CVE-2023-29534
- CVE-2023-29537
- CVE-2023-29538
- CVE-2023-29540
- CVE-2023-29543
- CVE-2023-29544
- CVE-2023-29546
- CVE-2023-29547
- CVE-2023-29549
- CVE-2023-29551
Frequently Asked Questions
What is CVE-2023-29541?
CVE-2023-29541 is a vulnerability in Firefox that allows for the execution of attacker-controlled commands through downloaded files ending in '.desktop'.
Which operating systems are affected by CVE-2023-29541?
Only Firefox for Linux on certain distributions is affected by CVE-2023-29541.
How severe is CVE-2023-29541?
CVE-2023-29541 has a severity rating of medium.
How can I fix CVE-2023-29541?
To fix CVE-2023-29541, ensure you have updated to the latest version of Firefox for Linux on the affected distributions.
Where can I find more information about CVE-2023-29541?
You can find more information about CVE-2023-29541 at the following links: [Mozilla Advisory](https://www.mozilla.org/security/advisories/mfsa2023-14/), [Mozilla Advisory](https://www.mozilla.org/security/advisories/mfsa2023-13/), [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1810191).