PT-2015-1039 · Mozilla+3 · Firefox+3
Armin Ebert
+1
·
Publicado
2015-03-31
·
Atualizado
2024-12-12
·
CVE-2015-0812
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 37.0
Description
The issue allows an attacker controlling network traffic to bypass user authentication by deploying a specially crafted website and conducting a DNS spoofing attack against a mozilla.org subdomain. This is possible because the browser does not require an HTTPS session for lightweight theme add-on installations.
Recommendations
For versions prior to 37.0, update to version 37.0 or later to resolve the issue. As a temporary workaround, consider restricting the installation of lightweight theme add-ons to only those that use HTTPS connections, and avoid using unsecured networks to minimize the risk of exploitation.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Firefox
Suse
Ubuntu