CVE-2024-5690: Medium severity Mozilla Thunderbird vulnerability
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 131.0.3-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 128.3.1esr-1~deb11u1Fixed in 115.14.0esr-1~deb12u1Fixed in 128.3.1esr-1~deb12u1Fixed in 128.3.1esr-2 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:115.16.0esr-1~deb11u1Fixed in 1:115.12.0-1~deb12u1Fixed in 1:115.16.0esr-1~deb12u1Fixed in 1:128.2.0esr-1Fixed in 1:128.3.0esr-1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 115.12 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 127 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.12 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 115.12 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 115.12
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-5690?
CVE-2024-5690 is classified as a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2024-5690?
To mitigate CVE-2024-5690, update to the latest versions of affected software including Firefox ESR 115.14, Thunderbird 115.14, or other specified versions.
Which software is affected by CVE-2024-5690?
CVE-2024-5690 affects Mozilla Firefox ESR versions prior to 115.14 and Mozilla Thunderbird versions prior to 115.14.
Can CVE-2024-5690 be exploited remotely?
Yes, CVE-2024-5690 can potentially be exploited by attackers remotely through crafted external protocol handlers.
What impact does CVE-2024-5690 have?
CVE-2024-5690 may allow an attacker to discern which external protocol handlers are functional on a user's system, leading to potential exploitation.