CVE-2024-8383: High severity thunderbird vulnerability
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.
Other sources
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.
— Debian
Thunderbird normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8383?
CVE-2024-8383 has a moderate severity rating due to potential exposure to untrusted applications handling Usenet-related schemes.
How do I fix CVE-2024-8383?
To fix CVE-2024-8383, update Firefox or Thunderbird to the latest recommended versions: for Firefox to 130.0 or higher and for Thunderbird to 128.2 or higher.
Which versions of Firefox are affected by CVE-2024-8383?
Versions of Firefox earlier than 130.0 and versions of Firefox ESR earlier than 115.15 are affected by CVE-2024-8383.
Which versions of Thunderbird are impacted by CVE-2024-8383?
Thunderbird versions prior to 128.2 are impacted by CVE-2024-8383.
What actions are recommended for users regarding CVE-2024-8383?
Users should immediately update their affected versions of Firefox or Thunderbird to mitigate CVE-2024-8383.