PT-2018-3171 · Mozilla+2 · Firefox+2
Mathias Wu
·
Publicado
2018-10-23
·
Atualizado
2024-12-12
·
CVE-2018-12399
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 63
Description
The issue is related to the registration of new protocol handlers, where the API accepts a
title argument that can be misleading about the domain registering the handler. This may lead to users approving a protocol handler they otherwise would not have. The vulnerability is also described as being related to insufficient access control in the Firefox browser API, which could allow a remote attacker to substitute the user interface using a specially crafted title argument.Recommendations
For versions prior to 63, update to version 63 or later to resolve the issue. As a temporary workaround, consider restricting the approval of new protocol handlers to minimize the risk of exploitation.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Firefox
Ubuntu