First published: Tue Aug 29 2023(Updated: )
Excel .xll add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm.
Credit: security@mozilla.org security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <115.2 | 115.2 |
Mozilla Thunderbird | <115.2 | 115.2 |
Mozilla Thunderbird | <102.15 | 102.15 |
Mozilla Firefox ESR | <102.15 | 102.15 |
Mozilla Firefox | <117 | 117 |
Mozilla Firefox | <117.0 | |
Mozilla Firefox ESR | <102.15 | |
Mozilla Firefox ESR | >=115.0<115.2 | |
Mozilla Thunderbird | <115.2 | |
redhat/firefox | <102.15 | 102.15 |
redhat/thunderbird | <102.15 | 102.15 |
redhat/firefox | <115.2 | 115.2 |
redhat/thunderbird | <115.2 | 115.2 |
Mozilla Firefox | >=115.0<115.2 | |
debian/firefox | 134.0.2-2 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.6.0esr-1~deb11u3 128.5.0esr-1~deb12u1 128.6.0esr-1~deb12u1 128.5.0esr-1 128.6.0esr-4 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:128.6.0esr-1~deb11u1 1:128.5.0esr-1~deb12u1 1:128.6.0esr-1~deb12u1 1:128.6.0esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2023-4581.
This vulnerability affects Firefox versions older than 117, Firefox ESR versions older than 102.15, Thunderbird versions older than 102.15, and Thunderbird versions older than 115.2.
The severity level of CVE-2023-4581 is medium.
To fix this vulnerability, update Firefox to version 117 or newer, Firefox ESR to version 102.15 or newer, Thunderbird to version 102.15 or newer, and Thunderbird to version 115.2 or newer.
You can find more information about CVE-2023-4581 in the following references: - [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1843758) - [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2023-36/) - [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2023-37/)