CVE-2023-29539: Null Pointer Dereference
Last updated 24 July 2024
Other sources
When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-29531
- CVE-2023-29532
- CVE-2023-29533
- CVE-2023-1999
- CVE-2023-29535
- CVE-2023-29536
- CVE-2023-0547
- CVE-2023-29479
- CVE-2023-29539
- CVE-2023-29541
- CVE-2023-29542
- CVE-2023-29545
- CVE-2023-1945
- CVE-2023-29548
- CVE-2023-29550
- CVE-2023-29534
- CVE-2023-29537
- CVE-2023-29538
- CVE-2023-29540
- CVE-2023-29543
- CVE-2023-29544
- CVE-2023-29546
- CVE-2023-29547
- CVE-2023-29549
- CVE-2023-29551
Frequently Asked Questions
What is CVE-2023-29539?
CVE-2023-29539 is a vulnerability that affects Firefox and Thunderbird, allowing for reflected file download attacks potentially tricking users to install malware.
Which software versions are affected by CVE-2023-29539?
Firefox versions less than 112, Thunderbird versions less than 102.10, and some Ubuntu and Debian packages are affected.
What is the severity of CVE-2023-29539?
CVE-2023-29539 has a severity level of medium.
How can I fix CVE-2023-29539?
To fix CVE-2023-29539, update your Firefox or Thunderbird to version 112 or higher, and update any affected Ubuntu or Debian packages to the recommended versions.
Where can I find more information about CVE-2023-29539?
You can find more information about CVE-2023-29539 on the Mozilla website and the Bugzilla page.