PT-2019-5027 · Mozilla+2 · Firefox+2

Paul Theriault

·

Publicado

2019-10-22

·

Atualizado

2024-12-12

·

CVE-2019-11765

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 70
Description The issue is related to a lack of validation in the parent process of Firefox, which could allow an attacker to grant attacker-controlled permissions instead of the 'Click to Play' permission when a user accepts a permission request. This could potentially impact the integrity of data.
Recommendations For versions prior to 70, update to version 70 or later to resolve the issue. As a temporary workaround, consider disabling the 'Click to Play' feature until a patch is available. Restrict access to sensitive data and permissions to minimize the risk of exploitation.

Correção

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-3087
ALT-PU-2020-1617
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2021-1368
BDU:2020-01660
CVE-2019-11765
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-4165-1
USN-4165-2

Produtos afetados

Alt Linux
Firefox
Ubuntu