PT-2019-5027 · Mozilla+2 · Firefox+2
Paul Theriault
·
Publicado
2019-10-22
·
Atualizado
2024-12-12
·
CVE-2019-11765
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 70
Description
The issue is related to a lack of validation in the parent process of Firefox, which could allow an attacker to grant attacker-controlled permissions instead of the 'Click to Play' permission when a user accepts a permission request. This could potentially impact the integrity of data.
Recommendations
For versions prior to 70, update to version 70 or later to resolve the issue. As a temporary workaround, consider disabling the 'Click to Play' feature until a patch is available. Restrict access to sensitive data and permissions to minimize the risk of exploitation.
Correção
Incorrect Default Permissions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Firefox
Ubuntu