CVE-2023-4052
01.08.2023, 15:15
The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privileged user. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1.
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 116.0 |
mozilla | firefox_esr | 𝑥 < 115.1 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||
firefox-esr |
| ||||||||||||
thunderbird |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||||||
mozjs102 |
| ||||||||||||||||
mozjs38 |
| ||||||||||||||||
mozjs52 |
| ||||||||||||||||
mozjs68 |
| ||||||||||||||||
mozjs78 |
| ||||||||||||||||
mozjs91 |
| ||||||||||||||||
thunderbird |
|
References