PT-2018-3171 · Mozilla+2 · Firefox+2

Mathias Wu

·

Publicado

2018-10-23

·

Atualizado

2024-12-12

·

CVE-2018-12399

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 63
Description The issue is related to the registration of new protocol handlers, where the API accepts a title argument that can be misleading about the domain registering the handler. This may lead to users approving a protocol handler they otherwise would not have. The vulnerability is also described as being related to insufficient access control in the Firefox browser API, which could allow a remote attacker to substitute the user interface using a specially crafted title argument.
Recommendations For versions prior to 63, update to version 63 or later to resolve the issue. As a temporary workaround, consider restricting the approval of new protocol handlers to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2645
ALT-PU-2019-2324
ALT-PU-2019-2486
BDU:2019-04302
CVE-2018-12399
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3801-1
USN-3801-2

Produtos afetados

Alt Linux
Firefox
Ubuntu