REDHAT-BUG-2362902: High severity firefox vulnerability
Mozilla Firefox's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2362902?
The severity of REDHAT-BUG-2362902 is classified as medium.
How do I fix REDHAT-BUG-2362902?
To fix REDHAT-BUG-2362902, ensure you update your Mozilla Firefox or Thunderbird applications to the latest recommended versions.
Which versions are affected by REDHAT-BUG-2362902?
REDHAT-BUG-2362902 affects Mozilla Firefox versions before 139, Mozilla Firefox ESR before 129, and Mozilla Thunderbird versions before 139.
What type of vulnerability is REDHAT-BUG-2362902?
REDHAT-BUG-2362902 is a code injection vulnerability that allows for interference with SYSTEM-level operations.
Can an attacker exploit REDHAT-BUG-2362902 remotely?
No, REDHAT-BUG-2362902 requires local access to exploit the vulnerability.