Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-25743
HistoryJun 02, 2023 - 12:00 a.m.

CVE-2023-25743

2023-06-0200:00:00
ubuntu.com
ubuntu.com
14
firefox
fullscreen mode
notification
vulnerability
spoofing
firefox focus

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

37.7%

A lack of in app notification for entering fullscreen mode could have lead
to a malicious website spoofing browser chrome.<br>This bug only affects
Firefox Focus. Other versions of Firefox are unaffected.
. This
vulnerability affects Firefox < 110 and Firefox ESR < 102.8.

Notes

Author Note
tyhicks mozjs contains a copy of the SpiderMonkey JavaScript engine
mdeslaur starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap only affects firefox focus

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

37.7%