Описание
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | not-affected  | code not present | 
| esm-infra/focal | DNE  | |
| focal | ignored  | end of standard support, was needed | 
| jammy | not-affected  | code not present | 
| noble | not-affected  | code not present | 
| oracular | not-affected  | code not present | 
| plucky | not-affected  | code not present | 
| questing | not-affected  | code not present | 
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/noble | ignored  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | ignored  | |
| noble | ignored  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| noble | ignored  | |
| oracular | ignored  | |
| plucky | ignored  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/bionic | needs-triage  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/focal | ignored  | |
| esm-infra/bionic | ignored  | |
| focal | ignored  | |
| jammy | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | ignored  | |
| focal | ignored  | |
| jammy | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/jammy | ignored  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | ignored  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | ignored  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | not-affected  | code not present | 
| esm-infra/focal | DNE  | |
| focal | ignored  | end of standard support, was needed | 
| jammy | released  | 1:128.12.0+build1-0ubuntu0.22.04.1 | 
| noble | not-affected  | code not present | 
| oracular | not-affected  | code not present | 
| plucky | not-affected  | code not present | 
| questing | not-affected  | code not present | 
| upstream | released  | 128.11 | 
Показывать по
Ссылки на источники
4.8 Medium
CVSS3
Связанные уязвимости
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
Due to insufficient escaping of the newline character in the \u201cCop ...
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.
Уязвимость функции Copy as cURL браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю выполнить произвольный код
4.8 Medium
CVSS3