CERT-In Vulnerability Note
CIVN-2023-0082
Multiple Vulnerabilities in Mozilla Products
Original Issue Date:March 21, 2023
Severity Rating: HIGH
Software Affected
- Mozilla Firefox versions prior to 111
- Mozilla Firefox ESR versions prior to 102.9
- Mozilla Thunderbird versions prior to 102.9
Overview
Multiple vulnerabilities have been reported in Mozilla Firefox, Mozilla Firefox ESR and Mozilla Thunderbird which could be exploited by an attacker to execute arbitrary code, disclose sensitive information or perform spoofing attack on the targeted system.
Description
These vulnerabilities exist in Mozilla products due to potential service worker cache leak during private browsing mode , Incorrect code generation during JIT compilation , Hiding of Fullscreen notification by download popups on Android , Opening of third-party apps without a prompt in Firefox for android, Leak of local path while redirecting to web extension files, Dragging a URL from a cross-origin iframe that was removed during the drag, Extension of permission to other local files loaded in the same tab while granting one-time permissions to a local file, Invalid downcast in worklets, Potential out-of-bounds when accessing throttled streams ,Windows save as dialog resolved environment variables and Memory safety bugs. An attacker could exploit these vulnerabilities by persuading a victim to visit a specially crafted web site.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, disclose sensitive information or perform spoofing attack on the targeted system.
Solution
Apply appropriate fixes issued by the vendor: - Upgrade to Mozilla Firefox version 111
- Upgrade to Mozilla Firefox ESR version 102.9
- Upgrade to Mozilla Thunderbird version 102.9
Vendor Information
Mozilla
https://www.mozilla.org/en-US/security/advisories/
References
Mozilla
https://www.mozilla.org/en-US/security/advisories/mfsa2023-09/
https://www.mozilla.org/en-US/security/advisories/mfsa2023-10/
https://www.mozilla.org/en-US/security/advisories/mfsa2023-11/
CVE Name
CVE-2023-25748
CVE-2023-25749
CVE-2023-25750
CVE-2023-25751
CVE-2023-25752
CVE-2023-28159
CVE-2023-28160
CVE-2023-28161
CVE-2023-28162
CVE-2023-28163
CVE-2023-28164
CVE-2023-28176
CVE-2023-28177
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|