CVE-2023-29541
moderate-risk
Published 2023-06-02
Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
Do I need to act?
-
0.21% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10
High
NETWORK
/ LOW complexity
Affected Products (5)
Affected Vendors
References (8)
Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=1810191
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2023-13/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2023-14/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2023-15/
Issue Tracking
https://bugzilla.mozilla.org/show_bug.cgi?id=1810191
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2023-13/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2023-14/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2023-15/
43
/ 100
moderate-risk
Severity
30/34 · Critical
Exploitability
1/34 · Minimal
Exposure
12/34 · Low