REDHAT-BUG-2362907: High severity firefox vulnerability
A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2362907?
The severity of REDHAT-BUG-2362907 is considered high due to the potential for sandbox escape.
How do I fix REDHAT-BUG-2362907?
To address REDHAT-BUG-2362907, update Firefox or Thunderbird to the latest version that exceeds the affected versions.
Which versions are affected by REDHAT-BUG-2362907?
REDHAT-BUG-2362907 affects Firefox versions below 138 and Thunderbird versions below 138.
What are the impacts of REDHAT-BUG-2362907 on system security?
The impact of REDHAT-BUG-2362907 includes unauthorized execution of content in a user's browser, leading to potential data compromise.
Is REDHAT-BUG-2362907 specific to certain browsers?
Yes, REDHAT-BUG-2362907 specifically affects Mozilla Firefox and Thunderbird.