First published: Tue Nov 26 2024(Updated: )
When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <133 | |
Firefox ESR | <128.5 | |
Thunderbird | <133 | |
Thunderbird | <128.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2328950 is considered high due to the potential for malicious code execution.
To fix REDHAT-BUG-2328950, update to Firefox version 133 or later, Firefox ESR version 128.5 or later, Thunderbird version 133 or later, or Thunderbird ESR version 128.5 or later.
REDHAT-BUG-2328950 affects Mozilla Firefox versions below 133, Firefox ESR versions below 128.5, and Mozilla Thunderbird versions below 133.
An attacker can exploit REDHAT-BUG-2328950 to bypass the 'Open Executable File?' confirmation dialog, potentially leading to code execution.
There is no specific workaround for REDHAT-BUG-2328950; updating the software is recommended to mitigate the risk.