vulnerability

MFSA2023-14 Firefox: Security Vulnerabilities fixed in Firefox ESR 102.10 (CVE-2023-29542)

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Apr 11, 2023
Added
Apr 12, 2023
Modified
Jan 28, 2025

Description

A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code.

*This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox

Solution

mozilla-firefox-esr-upgrade-102_10
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.