PT-2019-4828 · Mozilla+5 · Firefox Esr+7

Gareth Heyes

·

Publicado

2019-10-22

·

Atualizado

2024-12-12

·

CVE-2019-11763

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 70 Thunderbird versions prior to 68.2 Firefox ESR versions prior to 68.2
Description The issue arises from the incorrect handling of null bytes when processing HTML entities, leading to incorrect parsing by Firefox. This could result in HTML comment text being treated as HTML, potentially leading to cross-site scripting (XSS) in certain web applications. Additionally, it could allow HTML entities to be masked from filters, enabling the use of entities to hide actual characters of interest from filters. The vulnerability may allow a remote attacker to impact data integrity.
Recommendations For Firefox versions prior to 70, update to version 70 or later. For Thunderbird versions prior to 68.2, update to version 68.2 or later. For Firefox ESR versions prior to 68.2, update to version 68.2 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-3056
ALT-PU-2019-3087
ALT-PU-2019-3106
ALT-PU-2020-1166
ALT-PU-2020-1515
ALT-PU-2020-1617
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2021-1368
BDU:2020-01412
CESA-2019_3193
CESA-2019_3196
CESA-2019_3210
CESA-2019_3237
CESA-2019_3281
CESA-2019_3756
CVE-2019-11763
DLA-1987-1
DLA-1997-1
DSA-4549-1
DSA-4571-1
DSA-4571-2
MGASA-2019-0315
MGASA-2019-0316
OPENSUSE-SU-2019:2451-1
OPENSUSE-SU-2019:2452-1
OPENSUSE-SU-2019:2459-1
OPENSUSE-SU-2019:2464-1
OPENSUSE-SU-2019_2451-1
OPENSUSE-SU-2019_2452-1
OPENSUSE-SU-2019_2459-1
OPENSUSE-SU-2019_2464-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2019:3193
RHSA-2019:3196
RHSA-2019:3210
RHSA-2019:3237
RHSA-2019:3281
RHSA-2019:3756
RHSA-2019_3193
RHSA-2019_3196
RHSA-2019_3210
RHSA-2019_3237
RHSA-2019_3281
RHSA-2019_3756
SUSE-SU-2019:14246-1
SUSE-SU-2019:2871-1
SUSE-SU-2019:2872-1
SUSE-SU-2019:2912-1
SUSE-SU-2019_14246-1
USN-4165-1
USN-4165-2
USN-4202-1
USN-4202-2
USN-4335-1

Produtos afetados

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Ubuntu