REDHAT-BUG-2368751: Medium severity firefox vulnerability
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2368751?
The severity of REDHAT-BUG-2368751 is significant as it may lead to local code execution through crafted cURL commands.
How do I fix REDHAT-BUG-2368751?
To fix REDHAT-BUG-2368751, update to Firefox version 139 or later, or Firefox ESR version 115.24 or later.
Which versions of Firefox are affected by REDHAT-BUG-2368751?
Firefox versions earlier than 139 and Firefox ESR versions earlier than 115.24 are affected by REDHAT-BUG-2368751.
What can an attacker do with REDHAT-BUG-2368751?
An attacker can exploit REDHAT-BUG-2368751 to trick users into executing harmful commands on their local systems.
Is this vulnerability present in Firefox ESR?
Yes, REDHAT-BUG-2368751 affects Firefox ESR versions earlier than 115.24.