CVE-2023-29541
Published: Jun 2, 2023
Modified: Jan 10, 2025
Description
Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox | affected unspecified - < 112 |
Mozilla | Focus for Android | affected unspecified - < 112 |
Mozilla | Firefox ESR | affected unspecified - < 102.10 |
Mozilla | Firefox for Android | affected unspecified - < 112 |
Mozilla | Thunderbird | affected unspecified - < 102.10 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now