CVE-2023-25734
02.06.2023, 17:15
After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
| Vendor | Product | Version |
|---|---|---|
| mozilla | firefox | 𝑥 < 110.0 |
| mozilla | firefox_esr | 𝑥 < 102.8 |
| mozilla | thunderbird | 𝑥 < 102.8 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| firefox |
| ||||||||||||
| firefox-esr |
| ||||||||||||
| thunderbird |
|
Ubuntu Releases
Common Weakness Enumeration
References