VDB
BDU%3A2023-04018
BDU%3A2023-04018
PUBLISHED
CVSS 7.199999809265137 HIGH
Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с отсутствием предупреждения при открытии Diagcab-файлов, позволяющая нарушителю выполнить спуфинг-атаки
Risk Scores
CVSS 2.0
7.199999809265137
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «РусБИТех-Астра», Novell Inc., Сообщество свободного программного обеспечения, Canonical Ltd., ООО «Ред Софт», Mozilla Corp., АО "НППКТ", АО «ИВК» | Astra Linux Special Edition (запись в едином реестре российских программ №369), Suse Linux Enterprise Desktop, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Software Development Kit, SUSE OpenStack Cloud, Suse Linux Enterprise Server, SUSE Linux Enterprise Module for Desktop Applications, SUSE Linux Enterprise Workstation Extension, SUSE OpenStack Cloud Crowbar, Debian GNU/Linux, SUSE Enterprise Storage, HPE Helion Openstack, SUSE Linux Enterprise High Performance Computing, Ubuntu, SUSE Manager Proxy, SUSE Manager Retail Branch Server, SUSE Manager Server, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise Real Time, SUSE Linux Enterprise Module for Package Hub, Firefox, Firefox ESR, Thunderbird, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), АЛЬТ СП 10 |
Timeline
- Jul 25, 2023 CVE Published
- Nov 11, 2024 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
References
- https://www.mozilla.org/security/advisories/mfsa2023-22/ url
- https://www.mozilla.org/security/advisories/mfsa2023-23/ url
- https://www.mozilla.org/security/advisories/mfsa2023-24/ url
- https://www.debian.org/security/2023/dsa-5450 url
- https://www.debian.org/security/2023/dsa-5451 url
- https://bugzilla.mozilla.org/show_bug.cgi?id=1816287 url
- https://lists.debian.org/debian-lts-announce/2023/07/msg00006.html url
- https://lists.debian.org/debian-lts-announce/2023/07/msg00015.html url
- https://www.suse.com/security/cve/CVE-2023-37208.html url
- https://ubuntu.com/security/CVE-2023-37208 url
- https://security-tracker.debian.org/tracker/CVE-2023-37208 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.8/ url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2024-0830SE17 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20220829SE16 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2024-1031SE47 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20231214SE16 advisory