CVE-2023-29542

CRITICAL

Firefox < 112 & Thunderbird < 102.10 - Info Disclosure

Title source: llm
STIX 2.1

Description

A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

Scores

CVSS v3 9.8
EPSS 0.0013
EPSS Percentile 32.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

Status published
Products (3)
mozilla/firefox < 112.0
mozilla/firefox_esr < 102.10
mozilla/thunderbird < 102.10
Published Jun 19, 2023
Tracked Since Feb 18, 2026