Wind River Support Network

HomeDefectsLIN1022-6560
Not to be fixed

LIN1022-6560 : Security Advisory - firefox - CVE-2024-1550

Created: Feb 20, 2024    Updated: Apr 8, 2024
Resolved Date: Apr 8, 2024
Found In Version: 10.22.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CREATE(Triage):(User=admin) CVE-2024-1550 (https://nvd.nist.gov/vuln/detail/CVE-2024-1550)
Live chat
Online