PT-2016-6339 · Mozilla+3 · Firefox+3

Rafael Gieschke

·

Publicado

2016-09-20

·

Atualizado

2024-12-12

·

CVE-2016-5279

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 49.0
Description The issue allows remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code. This can be achieved when a user is tricked into performing a specific action, such as dragging and dropping a file.
Recommendations For versions prior to 49.0, update to version 49.0 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2049
ALT-PU-2017-1578
CVE-2016-5279
OPENSUSE-SU-2016_2368-1
OPENSUSE-SU-2016_2386-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-3076-1

Produtos afetados

Alt Linux
Firefox
Suse
Ubuntu