CVE-2023-37208: Malicious File Upload
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Other sources
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-23/#CVE-2023-37208
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/firefoxto a version that resolves this vulnerability.Fixed in 115.0-1 - Upgrade
Upgrade
ubuntu/firefoxto a version that resolves this vulnerability.Fixed in 115.0+ - Upgrade
Upgrade
ubuntu/thunderbirdto a version that resolves this vulnerability.Fixed in 1:102.13.0+ - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 102.13 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 102.13 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 123.0-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.8.0esr-1~deb10u1Fixed in 115.7.0esr-1~deb11u1Fixed in 115.8.0esr-1~deb11u1Fixed in 115.7.0esr-1~deb12u1Fixed in 115.8.0esr-1~deb12u1Fixed in 115.8.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.8.0-1~deb10u1Fixed in 1:115.7.0-1~deb11u1Fixed in 1:115.8.0-1~deb11u1Fixed in 1:115.7.0-1~deb12u1Fixed in 1:115.8.0-1~deb12u1Fixed in 1:115.7.0-1Fixed in 1:115.8.1-1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 102.13 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 115 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 102.13
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-37208.
Which software versions are affected by this vulnerability?
This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
What is the severity level of CVE-2023-37208?
The severity level of CVE-2023-37208 is medium.
How can I fix the vulnerability in Firefox?
To fix the vulnerability in Firefox, update to version 115 or later.
How can I fix the vulnerability in Thunderbird?
To fix the vulnerability in Thunderbird, update to version 102.13 or later.