You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups. This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected. This vulnerability affects Mozilla VPN client for Linux < v2.16.1.
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/mozilla-mobile/mozilla-vpn-client
vulnerable_at: 2.16.1+incompatible
packages:
- package: Mozilla VPN client for Linux
description: |-
An invalid Polkit Authentication check and missing authentication requirements
for D-Bus methods allowed any local user to configure arbitrary VPN setups.
*This bug only affects Mozilla VPN on Linux. Other operating systems are
unaffected.* This vulnerability affects Mozilla VPN client for Linux < v2.16.1.
cves:
- CVE-2023-4104
references:
- web: https://bugzilla.mozilla.org/show_bug.cgi?id=1831318
- fix: https://github.com/mozilla-mobile/mozilla-vpn-client/pull/7055
- fix: https://github.com/mozilla-mobile/mozilla-vpn-client/pull/7110
- fix: https://github.com/mozilla-mobile/mozilla-vpn-client/pull/7151
- advisory: https://www.mozilla.org/security/advisories/mfsa2023-39/
- web: https://www.openwall.com/lists/oss-security/2023/08/03/1
The text was updated successfully, but these errors were encountered:
CVE-2023-4104 references github.com/mozilla-mobile/mozilla-vpn-client, which may be a Go module.
Description:
An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups.
This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected. This vulnerability affects Mozilla VPN client for Linux < v2.16.1.
References:
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: