PT-2013-2625 · Mozilla+1 · Firefox+1

Shuichiro Suzuki

·

Publicado

2013-04-03

·

Atualizado

2013-06-05

·

CVE-2013-0798

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 20.0 on Android
Description The issue allows attackers to modify add-ons before installation by leveraging the time window during which the app tmp directory is used, due to world-writable and world-readable permissions for the app tmp installation directory in the local filesystem.
Recommendations For versions prior to 20.0 on Android, update to version 20.0 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-0798

Produtos afetados

Firefox
Suse