First published: Tue Aug 01 2023(Updated: )
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions.
Credit: security@mozilla.org security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <102.14 | 102.14 |
Mozilla Firefox ESR | <115.1 | 115.1 |
Mozilla Thunderbird | <115.1 | 115.1 |
Mozilla Thunderbird | <102.14 | 102.14 |
redhat/firefox | <102.14 | 102.14 |
redhat/firefox | <115.1 | 115.1 |
redhat/thunderbird | <102.14 | 102.14 |
redhat/thunderbird | <115.1 | 115.1 |
Mozilla Firefox | <116 | 116 |
Mozilla Firefox | <116.0 | |
Mozilla Firefox ESR | >=102.0<102.14 | |
Mozilla Firefox ESR | >=115.0<115.1 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 | |
Mozilla Firefox | >=102.0<102.14 | |
Mozilla Firefox | >=115.0<115.1 | |
debian/firefox | 133.0.3-1 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.5.0esr-1~deb11u1 128.3.1esr-1~deb12u1 128.5.0esr-1~deb12u1 128.5.0esr-1 128.5.1esr-1 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:128.5.0esr-1~deb11u1 1:115.16.0esr-1~deb12u1 1:128.5.0esr-1~deb12u1 1:128.5.0esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID for this bug in popup notifications delay calculation is CVE-2023-4047.
This vulnerability affects Firefox versions < 116, Firefox ESR versions < 102.14, and Thunderbird versions < 115.1.
The severity rating of CVE-2023-4047 is high (8.8).
To fix the vulnerability in Firefox, update to version 116 or later. To fix the vulnerability in Thunderbird, update to version 115.1 or later.
You can find more information about CVE-2023-4047 on the Mozilla Security Advisories page: [Link](https://www.mozilla.org/security/advisories/mfsa2023-30/)