If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1878577 | vendor advisory issue tracking exploit |
https://www.mozilla.org/security/advisories/mfsa2024-21/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2024-22/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2024-23/ | vendor advisory |
https://lists.debian.org/debian-lts-announce/2024/05/msg00010.html | mailing list |
https://lists.debian.org/debian-lts-announce/2024/05/msg00012.html | mailing list |