CVE-2024-5692
11.06.2024, 13:15
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 < 115.12 |
mozilla | firefox | 𝑥 < 127.0 |
mozilla | thunderbird | 𝑥 < 115.12 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||
firefox-esr |
| ||||||||||||
thunderbird |
|
References