Security features bypass in Mozilla Firefox and Firefox ESR - CVE-2023-25734
Published: February 15, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to an error when handling Windows .url shortcuts that are opened by the browser from the local filesystem. A remote attacker can trick the victim into launching a specially crafted shortcut that then initiates network requests from the operating system to the malicious server. A remote attacker can obtain potentially sensitive information including NTLM credentials.
Note, the vulnerability affects Windows installations only.
Affected software
Firefox ESR
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Oracle Solaris
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 12 SP4 LTSS
Slackware Linux
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Package Hub 15
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
Mozilla Thunderbird
IBM Cloud Pak for Multicloud Management Monitoring
Synthetic Playback Agent
mozilla-thunderbird
mozilla-firefox
MozillaFirefox-translations-common
MozillaFirefox-devel
MozillaFirefox
MozillaFirefox-debugsource
MozillaFirefox-debuginfo
MozillaFirefox-translations-other
MozillaThunderbird-translations-common
MozillaThunderbird-debugsource
MozillaThunderbird-translations-other
MozillaThunderbird-debuginfo
MozillaThunderbird
MozillaFirefox-branding-upstream
mail-client/thunderbird
mail-client/thunderbird-bin
www-client/firefox
How to mitigate CVE-2023-25734
Firefox ESR - update to 102.8.0
Mozilla Thunderbird - update to 102.8.0
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
Synthetic Playback Agent - update to 8.1.4 IF18
mozilla-thunderbird - update to 102.8.0
mozilla-firefox - addressed in versions 102.8.0esr, 110.0
MozillaFirefox-translations-common - addressed in versions 102.8.0-112.150.1, 102.8.0-150000.150.76.1, 102.8.0-150200.152.78.1
MozillaFirefox-devel - addressed in versions 102.8.0-112.150.1, 102.8.0-150000.150.76.1, 102.8.0-150200.152.78.1
MozillaFirefox - addressed in versions 102.8.0-112.150.1, 102.8.0-150000.150.76.1, 102.8.0-150200.152.78.1
MozillaFirefox-debugsource - addressed in versions 102.8.0-112.150.1, 102.8.0-150000.150.76.1, 102.8.0-150200.152.78.1
MozillaFirefox-debuginfo - addressed in versions 102.8.0-112.150.1, 102.8.0-150000.150.76.1, 102.8.0-150200.152.78.1
MozillaFirefox-translations-other - addressed in versions 102.8.0-150000.150.76.1, 102.8.0-150200.152.78.1
MozillaThunderbird-translations-common - update to 102.8.0-150200.8.105.2
MozillaThunderbird-debugsource - update to 102.8.0-150200.8.105.2
MozillaThunderbird-translations-other - update to 102.8.0-150200.8.105.2
MozillaThunderbird-debuginfo - update to 102.8.0-150200.8.105.2
MozillaThunderbird - update to 102.8.0-150200.8.105.2
MozillaFirefox-branding-upstream - update to 102.8.0-150200.152.78.1
mail-client/thunderbird - update to 102.10.0
mail-client/thunderbird-bin - update to 102.10.0
www-client/firefox - update to 104
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox and Firefox ESR
- Slackware Linux update for mozilla-firefox
- Multiple vulnerabilities in Mozilla Thunderbird
- Slackware Linux update for mozilla-thunderbird
- SUSE update for MozillaFirefox
- SUSE update for MozillaFirefox
- SUSE update for MozillaFirefox
- SUSE update for MozillaThunderbird
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in APM Synthetic Playback Agent
- Gentoo update for Mozilla Thunderbird
- Gentoo update for Mozilla Firefox
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Monitoring