Input validation error in Mozilla Firefox and Firefox for Android - CVE-2023-4579
Published: August 29, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a spoofing attack.
The vulnerability exists due to insufficient validation of user-supplied input when handling persistent search terms. Search queries in the default search engine can appear to have been the currently navigated URL if the search query itself is a well formed URL. As a result, a remote attacker can perform a spoofing attack if it had been maliciously set as the default search engine.
Affected software
Firefox for Android
Gentoo Linux
Ubuntu
openEuler
www-client/firefox
firefox (Ubuntu package)
firefox
firefox-debuginfo
firefox-debugsource
How to mitigate CVE-2023-4579
www-client/firefox - update to 104
firefox (Ubuntu package) - update to 117.0+build2-0ubuntu0.20.04.1
firefox - update to 128.8.0-1
firefox-debuginfo - update to 128.8.0-1
firefox-debugsource - update to 128.8.0-1