External control of file name or path In thunderbird
Description
Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placing files in the installation directory. Note: This issue only affected Windows operating systems. Other operating systems are unaffected.. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component |
|---|---|
rpm rhel6 | |
rpm rhel7 | |
rpm rhel8 | |
rpm rhel5 | |
rpm rhel6 | |
rpm rhel7 | |
rpm rhel8 |
Aliases
1. 2. 3.