PT-2015-1896 · Mozilla+1 · Firefox+2

James Forshaw

·

Publicado

2015-08-11

·

Atualizado

2024-12-12

·

CVE-2015-4481

CVSS v2.0

3.3

Baixa

VetorAV:L/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 40.0 Mozilla Firefox ESR versions prior to 38.2
Description The issue is caused by a race condition in the Mozilla Maintenance Service, allowing local users to write to arbitrary files and gain privileges. This is achieved through vectors involving a hard link to a log file during an update. The vulnerability is related to synchronization errors when using a shared resource, which can be exploited by a local attacker to manipulate hard links to log files and elevate privileges.
Recommendations For Mozilla Firefox versions prior to 40.0, update to version 40.0 or later to resolve the issue. For Mozilla Firefox ESR versions prior to 38.2, update to version 38.2 or later to resolve the issue.

Exploit

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11242
CVE-2015-4481
OPENSUSE-SU-2015_1389-1
OPENSUSE-SU-2015_1390-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1

Produtos afetados

Firefox
Firefox Esr
Suse