Vulnerability CVE-2024-1550: Information

Description

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

Published: Feb. 20, 2024
Modified: March 4, 2024

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus123.0-alt1125.0.2-alt1ALT-PU-2024-2933-1341362Fixed
firefoxsisyphus_riscv64123.0-alt0.port124.0.1-alt0.portALT-PU-2024-3300-1-Fixed
firefoxsisyphus_loongarch64123.0-alt1.0.port125.0.1-alt1.0.portALT-PU-2024-3000-1-Fixed
firefox-esrsisyphus115.8.0-alt1115.10.0-alt1ALT-PU-2024-2827-2341225Fixed
firefox-esrsisyphus_loongarch64115.8.0-alt1115.10.0-alt1ALT-PU-2024-2999-1-Fixed
firefox-esrp10115.8.0-alt1115.10.0-alt1ALT-PU-2024-2835-2341263Fixed
firefox-esrc10f1115.8.0-alt0.c10.1115.9.1-alt0.c10.1ALT-PU-2024-3614-2340631Fixed
thunderbirdsisyphus115.8.0-alt1115.9.0-alt1ALT-PU-2024-2870-2341315Fixed
thunderbirdsisyphus_loongarch64115.8.0-alt1115.9.0-alt1ALT-PU-2024-3069-1-Fixed
thunderbirdp10115.8.1-alt1115.9.0-alt1ALT-PU-2024-3860-2342581Fixed
thunderbirdc10f1115.8.1-alt0.c10.1115.9.0-alt0.c10.1ALT-PU-2024-4748-2343092Fixed

References to Advisories, Solutions, and Tools