CVE-2023-29541

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jun 2, 2023
Updated: Jan 10, 2025
CWE ID 116

Summary

CVE-2023-29541 is a vulnerability affecting Firefox for Linux on select distributions. The browser fails to adequately manage downloads of files with a .desktop extension, potentially enabling attackers to execute unintended commands. This flaw is present in Firefox versions below 112, Focus for Android below 112, Firefox ESR below 102.10, Firefox for Android below 112, and Thunderbird below 102.10. Mozilla has yet to identify all impacted Linux distributions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share