PT-2019-4562 · Mozilla+2 · Firefox+2

Abdulrahman Alqabandi

·

Publicado

2019-05-21

·

Atualizado

2024-12-12

·

CVE-2019-11696

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 67
Description The issue concerns the handling of executable content for applications with the .JNLP extension, which are used for "Java web start" applications. These files are not treated as executable content for download prompts, even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally. Exploitation of this issue may allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For versions prior to 67, update to version 67 or later to resolve the issue. As a temporary workaround, consider disabling the execution of .JNLP files until a patch is applied. Restrict access to Java web start applications to minimize the risk of exploitation. Avoid launching executable binaries locally from download prompts to prevent potential attacks.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1941
ALT-PU-2019-2324
ALT-PU-2019-2479
ALT-PU-2019-2486
BDU:2020-00608
CVE-2019-11696
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3991-1
USN-3991-2
USN-3991-3

Produtos afetados

Alt Linux
Firefox
Ubuntu