Rapid7 Vulnerability & Exploit Database

Oracle Linux: (CVE-2023-34414) (Multiple Advisories): firefox security update

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

Oracle Linux: (CVE-2023-34414) (Multiple Advisories): firefox security update

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
06/17/2023
Created
05/22/2024
Added
05/21/2024
Modified
05/21/2024

Description

The error page for sites with invalid TLS certificates was missing the

activation-delay Firefox uses to protect prompts and permission dialogs

from attacks that exploit human response time delays. If a malicious

page elicited user clicks in precise locations immediately before

navigating to a site with a certificate error and made the renderer

extremely busy at the same time, it could create a gap between when

the error page was loaded and when the display actually refreshed.

With the right timing the elicited clicks could land in that gap and

activate the button that overrides the certificate error for that site. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12.

Solution(s)

  • oracle-linux-upgrade-firefox
  • oracle-linux-upgrade-firefox-x11
  • oracle-linux-upgrade-thunderbird

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;