CVE-2024-1548: Medium severity Mozilla Thunderbird vulnerability
A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 123 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 137.0.2-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 128.9.0esr-1~deb11u1Fixed in 128.8.0esr-1~deb12u1Fixed in 128.9.0esr-1~deb12u1Fixed in 128.9.0esr-2 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:128.9.0esr-1~deb11u1Fixed in 1:128.8.0esr-1~deb12u1Fixed in 1:128.9.0esr-1~deb12u1Fixed in 1:128.9.0esr-1 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 123 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 115.8 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 115.8
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-1548?
CVE-2024-1548 has a moderate severity rating due to its potential to mislead users and facilitate spoofing attacks.
How do I fix CVE-2024-1548?
To fix CVE-2024-1548, users should update their Mozilla Firefox, Thunderbird, or Firefox ESR to versions that address this vulnerability.
Who is affected by CVE-2024-1548?
CVE-2024-1548 affects users of Mozilla Firefox, Thunderbird, and Firefox ESR versions prior to specified safe updates.
What types of attacks are possible with CVE-2024-1548?
CVE-2024-1548 could lead to user confusion and allow for spoofing attacks by obscuring fullscreen notifications.
Which versions of affected software should be updated to mitigate CVE-2024-1548?
Users should update to Firefox versions 123 and above, Thunderbird versions 115.8 and above, or Firefox ESR to mitigate CVE-2024-1548.