CVE-2024-11692: Medium severity thunderbird vulnerability
An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-11692?
CVE-2024-11692 is classified as a moderate severity vulnerability that may lead to user confusion and potential spoofing attacks.
How do I fix CVE-2024-11692?
To fix CVE-2024-11692, update Microsoft Thunderbird and Firefox to version 134 or later.
Which versions of software are affected by CVE-2024-11692?
CVE-2024-11692 affects Mozilla Thunderbird and Firefox versions up to 133, as well as Firefox ESR versions up to 128.5.
What types of attacks does CVE-2024-11692 enable?
CVE-2024-11692 may enable spoofing attacks due to select dropdowns being displayed over other tabs.
Is there a specific version for Debian that addresses CVE-2024-11692?
Yes, the fixed versions for Debian packages are firefox 134.0.2-3 and firefox-esr versions starting from 128.6.0esr.