The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2022-52/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2022-53/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2022-51/ | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1786188 | issue tracking permissions required |
https://security.gentoo.org/glsa/202305-06 | vendor advisory |
https://security.gentoo.org/glsa/202305-13 | vendor advisory |