PT-2017-16476 · Mozilla+3 · Firefox+3

Kris Maglione

·

Publicado

2017-01-24

·

Atualizado

2024-12-12

·

CVE-2017-5389

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 51
Description The issue allows a malicious extension to install additional extensions without explicit user permission by modifying the CSP headers on sites with the appropriate permissions and using host requests to redirect script loads to a malicious site. This is achieved through the use of the "mozAddonManager" API.
Recommendations For versions prior to 51, update to a version that includes the fix for this issue to prevent malicious extensions from installing additional extensions without user permission.

Exploit

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1138
ALT-PU-2017-1578
CVE-2017-5389
MGASA-2017-0323
OPENSUSE-SU-2017_0358-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3175-1
USN-3175-2

Produtos afetados

Alt Linux
Firefox
Suse
Ubuntu