First published: Tue Nov 21 2023(Updated: )
When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/firefox | <115.5 | 115.5 |
redhat/thunderbird | <115.5 | 115.5 |
ubuntu/firefox | <120.0+ | 120.0+ |
ubuntu/thunderbird | <1:115.5.0+ | 1:115.5.0+ |
ubuntu/thunderbird | <1:115.5.0+ | 1:115.5.0+ |
ubuntu/thunderbird | <1:115.5.0+ | 1:115.5.0+ |
ubuntu/thunderbird | <1:115.5.0+ | 1:115.5.0+ |
Mozilla Thunderbird | <115.5 | 115.5 |
Mozilla Firefox ESR | <115.5 | 115.5 |
Mozilla Firefox | <120.0 | |
Mozilla Firefox ESR | <115.5.0 | |
Mozilla Thunderbird | <115.5 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 | |
debian/firefox | 123.0-1 | |
debian/firefox-esr | <=91.12.0esr-1~deb10u1 | 115.8.0esr-1~deb10u1 115.7.0esr-1~deb11u1 115.8.0esr-1~deb11u1 115.7.0esr-1~deb12u1 115.8.0esr-1~deb12u1 115.8.0esr-1 |
debian/thunderbird | <=1:91.12.0-1~deb10u1 | 1:115.8.0-1~deb10u1 1:115.7.0-1~deb11u1 1:115.8.0-1~deb11u1 1:115.7.0-1~deb12u1 1:115.8.0-1~deb12u1 1:115.7.0-1 1:115.8.1-1 |
Mozilla Firefox | <120 | 120 |
Debian | =10.0 | |
Debian | =11.0 | |
Debian | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2023-6208.
This vulnerability affects Thunderbird on X11 and Firefox versions below 120 and below 115.5.
The severity rating of CVE-2023-6208 is medium with a value of 4.
When using X11, text selected by the page using the Selection API is erroneously copied into the primary selection.
To fix this vulnerability, update Thunderbird to version 115.5 or higher and update Firefox to version 120 or higher.