UBUNTU-CVE-2023-4052
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-4052
Summary:
Details: The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privileged user. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1.
References: https://ubuntu.com/security/CVE-2023-4052, https://bugzilla.mozilla.org/show_bug.cgi?id=1824420, https://www.mozilla.org/security/advisories/mfsa2023-31/, https://www.mozilla.org/security/advisories/mfsa2023-29/, https://www.cve.org/CVERecord?id=CVE-2023-4052
Affected packages
Package
Name: mozjs52
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
