PT-2015-2170 · Mozilla+3 · Firefox+3

Juho Nurminen

+1

·

Publicado

2015-09-22

·

Atualizado

2024-12-12

·

CVE-2015-4508

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 41.0
Description The issue allows remote attackers to spoof the relationship between address-bar URLs and web content via a crafted web site when reader mode is enabled. This can be exploited by a remote attacker to manipulate the content of the window using a specially formed website, which is related to errors in security settings.
Recommendations For versions prior to 41.0, update to version 41.0 or later to resolve the issue. As a temporary workaround, consider disabling the reader mode until a patch is available. Restrict access to crafted web sites to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1816
ALT-PU-2016-1454
BDU:2015-11516
CVE-2015-4508
MGASA-2015-0414
OPENSUSE-SU-2015_1658-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-2743-1
USN-2743-2
USN-2743-3
USN-2743-4

Produtos afetados

Alt Linux
Firefox
Suse
Ubuntu