First published: Tue Sep 03 2024(Updated: )
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <130 | |
Firefox ESR | <128.2<115.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2309429 is considered high due to the lack of user confirmation when handling unspecified schemes.
To fix REDHAT-BUG-2309429, update Mozilla Firefox to the latest version or apply relevant patches provided by Red Hat.
Firefox versions up to but not including 130 and Firefox ESR versions up to but not including 128.3 and 115.16 are affected by REDHAT-BUG-2309429.
The risks associated with REDHAT-BUG-2309429 include potential exploitation leading to the execution of untrusted code or safety violations when opening unsupported schemes.
A potential workaround for REDHAT-BUG-2309429 is to disable the offending Usenet-related schemes in the browser settings until an update is applied.