Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-0239

Опубликовано: 07 янв. 2025
Источник: debian
EPSS Низкий

Описание

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed134.0-1package
firefox-esrfixed128.6.0esr-1package
thunderbirdfixed1:128.6.0esr-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-01/#CVE-2025-0239

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-02/#CVE-2025-0239

  • https://www.mozilla.org/en-US/security/advisories/mfsa2025-05/#CVE-2025-0239

EPSS

Процентиль: 5%
0.00023
Низкий

Связанные уязвимости

CVSS3: 4
ubuntu
5 месяцев назад

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 5.4
redhat
5 месяцев назад

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 4
nvd
5 месяцев назад

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.

CVSS3: 4
github
5 месяцев назад

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

CVSS3: 5.4
fstec
5 месяцев назад

Уязвимость компонента Application-Layer Protocol Negotiation (ALPN) браузеров Mozilla Firefox, Firefox ESR и почтовых клиентов Thunderbird, Thunderbird ESR, позволяющая нарушителю перенаправить пользователя на произвольный URL-адрес

EPSS

Процентиль: 5%
0.00023
Низкий