Upstream information

CVE-2023-4579 at MITRE

Description

Search queries in the default search engine could appear to have been the currently navigated URL if the search query itself was a well formed URL. This could have led to a site spoofing another if it had been maliciously set as the default search engine. This vulnerability affects Firefox < 117.

SUSE information

Overall state of this security issue: New

This issue is currently rated as having not set severity.

CVSS v3 Scores
  National Vulnerability Database
Base Score 3.1
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality Impact None
Integrity Impact Low
Availability Impact None
CVSSv3 Version 3.1
No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • MozillaFirefox >= 117.0-1.1
  • MozillaFirefox-branding-upstream >= 117.0-1.1
  • MozillaFirefox-devel >= 117.0-1.1
  • MozillaFirefox-translations-common >= 117.0-1.1
  • MozillaFirefox-translations-other >= 117.0-1.1
Patchnames:
openSUSE Tumbleweed GA MozillaFirefox-117.0-1.1


SUSE Timeline for this CVE

CVE page created: Thu Aug 31 01:05:35 2023
CVE page last modified: Thu Sep 14 12:35:09 2023