PT-2019-1343 · Mozilla+5 · Firefox+5
Jann Horn
·
Publicado
2019-01-29
·
Atualizado
2024-12-12
·
CVE-2018-18506
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 65
Description
The issue is related to the Proxy Auto-Configuration (PAC) file in Firefox. When proxy auto-detection is enabled, a PAC file can be used to specify that requests to localhost are sent through a proxy to another server. This behavior can allow for attacks on services and tools that bind to localhost for networked behavior if accessed through browsing. The vulnerability can be exploited by a remote attacker using a specially crafted web page to bypass security restrictions during proxy auto-configuration, potentially leading to attacks on services bound to the local host.
Recommendations
For versions prior to 65, update to version 65 or later to resolve the issue. As a temporary workaround, consider disabling proxy auto-detection until a patch is available. Restrict access to the localhost to minimize the risk of exploitation. Avoid using the proxy auto-configuration feature in Firefox until the issue is resolved.
Exploit
Correção
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Firefox
Red Hat
Suse
Ubuntu