PT-2017-3680 · Mozilla+2 · Firefox+2

Andreas Pehrson

·

Publicado

2017-10-04

·

Atualizado

2024-12-12

·

CVE-2018-5109

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions prior to 58
Description: The issue is related to a flaw in the source confirmation mechanism, potentially allowing a remote attacker to gain unauthorized access to protected information. An audio capture session can be started under an incorrect origin, leading to user confusion about which site is making the request to capture an audio stream. Users are still prompted to allow the request, but the prompt may display the wrong origin.
Recommendations: For versions prior to 58, update to version 58 or later to resolve the issue. As a temporary workaround, consider restricting access to audio capture sessions to minimize the risk of exploitation. Avoid allowing audio capture requests from untrusted sites until the issue is resolved.

Correção

Origin Validation Error

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1178
ALT-PU-2018-1854
BDU:2018-00873
CVE-2018-5109
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3544-1
USN-3544-2

Produtos afetados

Alt Linux
Firefox
Ubuntu