First published: Tue Oct 01 2024(Updated: )
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 131.0.2-2 | |
debian/thunderbird | <=1:115.12.0-1~deb11u1<=1:115.15.0-1~deb11u1<=1:115.12.0-1~deb12u1<=1:115.15.0-1~deb12u1<=1:128.2.0esr-1 | 1:128.3.0esr-1 |
Thunderbird | <131 | 131 |
Thunderbird | <128.3 | 128.3 |
Firefox | <131.0 | |
Firefox ESR | <128.3.0 | |
Thunderbird | <128.3 | |
Thunderbird | =129.0-beta | |
Thunderbird | =129.0-beta2 | |
Thunderbird | =129.0-beta3 | |
Thunderbird | =129.0-beta4 | |
Thunderbird | =129.0-beta5 | |
Thunderbird | =129.0-beta6 | |
Firefox | <131 | 131 |
Firefox ESR | <128.3 | 128.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2024-9398 is considered a moderate severity vulnerability due to its potential to expose installed applications through protocol handlers.
To fix CVE-2024-9398, update Firefox to version 131 or later and Thunderbird to version 128.3 or later.
CVE-2024-9398 affects Firefox versions below 131, Firefox ESR versions below 128.3, and Thunderbird versions below 128.3.
Users of Firefox, Firefox ESR, and Thunderbird versions below the remedial versions are affected by CVE-2024-9398.
CVE-2024-9398 is a URL handler vulnerability that can reveal information about the applications installed on a user's system.