First published: Tue Nov 26 2024(Updated: )
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation process. As a result, the enforcement of signature validation for unrelated add-ons may have been bypassed. Signature validation in this context is used to ensure that third-party applications on the user's computer have not tampered with the user's extensions, limiting the impact of this issue. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <133 | |
Firefox ESR | <128.5 | |
Thunderbird | <133 | |
Thunderbird | <128.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2328943 is considered to be moderate due to potential disruption in signature validation.
To fix REDHAT-BUG-2328943, update to the latest versions of affected software such as Firefox and Thunderbird.
The affected systems include Mozilla Firefox versions up to 133, Firefox ESR versions up to 128.5, and Mozilla Thunderbird versions up to 133.
The vulnerability in REDHAT-BUG-2328943 is caused by the failure to handle exceptions during add-on signature verification from invalid or unsupported extension manifests.
Yes, REDHAT-BUG-2328943 can potentially lead to runtime errors that may disrupt the application and lead to system crashes.