Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8383

Опубликовано: 03 сент. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.

The Mozilla Foundation's Security Advisory: Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will.

Отчет

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6firefoxOut of support scope
Red Hat Enterprise Linux 9firefox:flatpak/firefoxWill not fix
Red Hat Enterprise Linux 7 Extended Lifecycle SupportfirefoxFixedRHSA-2024:683819.09.2024
Red Hat Enterprise Linux 8firefoxFixedRHSA-2024:668216.09.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportfirefoxFixedRHSA-2024:683919.09.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportfirefoxFixedRHSA-2024:689119.09.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicefirefoxFixedRHSA-2024:689119.09.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsfirefoxFixedRHSA-2024:689119.09.2024
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportfirefoxFixedRHSA-2024:689219.09.2024
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicefirefoxFixedRHSA-2024:689219.09.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2309429mozilla: Firefox did not ask before openings news: links in an external application

EPSS

Процентиль: 41%
0.00182
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.

CVSS3: 7.5
nvd
10 месяцев назад

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.

CVSS3: 7.5
debian
10 месяцев назад

Firefox normally asks for confirmation before asking the operating sys ...

CVSS3: 7.5
github
10 месяцев назад

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.

CVSS3: 7.5
fstec
10 месяцев назад

Уязвимость браузера Firefox, Firefox ESR, связанная с отсутствием диалогового окна подтверждения при открытии связанных с Usenet схем &quot;news:&quot; и &quot;snews:&quot;, позволяющая нарушителю загрузить произвольное приложение и выполнить произвольный код

EPSS

Процентиль: 41%
0.00182
Низкий

7.5 High

CVSS3