CVE-2023-4581: XLL file extensions were downloadable without warnings
Excel .xll add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm.
Other sources
Excel .xll add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-36/#CVE-2023-4581
— Red Hat
Excel .xll add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
— Launchpad
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-4581.
Which software is affected by this vulnerability?
This vulnerability affects Firefox versions older than 117, Firefox ESR versions older than 102.15, Thunderbird versions older than 102.15, and Thunderbird versions older than 115.2.
What is the severity level of CVE-2023-4581?
The severity level of CVE-2023-4581 is medium.
How can I fix this vulnerability?
To fix this vulnerability, update Firefox to version 117 or newer, Firefox ESR to version 102.15 or newer, Thunderbird to version 102.15 or newer, and Thunderbird to version 115.2 or newer.
Where can I find more information about CVE-2023-4581?
You can find more information about CVE-2023-4581 in the following references: - [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1843758) - [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2023-36/) - [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2023-37/)