PT-2015-1848 · Mozilla · Firefox Os

Muneaki Nishimura

·

Publicado

2015-08-06

·

Atualizado

2015-08-10

·

CVE-2015-2745

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox OS versions prior to 2.2
Description The issue allows remote attackers to inject arbitrary HTML via the name or title field in card content associated with a search link that is mishandled after a HOME button press or a Show Windows action. This can be demonstrated by embedding an arbitrary application or spoofing the account-creation page. The vulnerability exists due to the lack of protection of the web page structure in the Gaia Search app component of the Firefox OS.
Recommendations For versions prior to 2.2, update to version 2.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the Search app in Gaia until a patch is available. Avoid using the name and title fields in the search link card content to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11194
CVE-2015-2745

Produtos afetados

Firefox Os