Insufficient UI Warning of Dangerous Operations in Mozilla Firefox and Firefox ESR - CVE-2021-38510

 

Insufficient UI Warning of Dangerous Operations in Mozilla Firefox and Firefox ESR - CVE-2021-38510

Published: November 2, 2021


Vulnerability identifier: #VU57884
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38510
CWE-ID: CWE-357
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to silently download dangerous files on the system.

The vulnerability exists due to the executable file warning is not presented to the user when downloading .inetloc files. A remote attacker can silently download a potentially dangerous file to the user's system.

The vulnerability affects macOS operating system only.


Affected software

Mozilla Firefox
Firefox ESR
SUSE CaaS Platform
SUSE Enterprise Storage
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Module for Desktop Applications
Mozilla Thunderbird
MozillaFirefox-translations-common
MozillaFirefox-devel
MozillaFirefox-debugsource
MozillaFirefox-debuginfo
MozillaFirefox
MozillaFirefox-translations-other
MozillaThunderbird
MozillaThunderbird-debuginfo
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-translations-other

How to mitigate CVE-2021-38510

Install updates from vendor's website.

Mozilla Firefox - update to 94.0
Firefox ESR - update to 91.3.0
Mozilla Thunderbird - update to 91.3.0
MozillaFirefox-translations-common - addressed in versions 91.3.0-112.80.2, 91.3.0-150.6.1, 91.3.0-152.6.1
MozillaFirefox-devel - addressed in versions 91.3.0-112.80.2, 91.3.0-150.6.1, 91.3.0-152.6.1
MozillaFirefox-debugsource - addressed in versions 91.3.0-112.80.2, 91.3.0-150.6.1, 91.3.0-152.6.1
MozillaFirefox-debuginfo - addressed in versions 91.3.0-112.80.2, 91.3.0-150.6.1, 91.3.0-152.6.1
MozillaFirefox - addressed in versions 91.3.0-112.80.2, 91.3.0-150.6.1, 91.3.0-152.6.1
MozillaFirefox-translations-other - addressed in versions 91.3.0-150.6.1, 91.3.0-152.6.1
MozillaThunderbird - update to 91.4.0-8.45.2
MozillaThunderbird-debuginfo - update to 91.4.0-8.45.2
MozillaThunderbird-debugsource - update to 91.4.0-8.45.2
MozillaThunderbird-translations-common - update to 91.4.0-8.45.2
MozillaThunderbird-translations-other - update to 91.4.0-8.45.2

External References

Related Security Bulletins