PT-2023-2072 · Mozilla+3 · Firefox For Android+3

Kirtikumar Anandrao Ramchandani

·

Publicado

2023-03-14

·

Atualizado

2025-01-09

·

CVE-2023-25749

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Firefox for Android versions prior to 111
Description The issue is related to the Intent mechanism in Mozilla Firefox for Android, which can be exploited by a remote attacker to download arbitrary files due to the lack of request execution when opening third-party applications. This vulnerability can expose users to unpatched vulnerabilities in Android applications launched from the browser using Intents. To mitigate this, Firefox now confirms with users before launching external applications.
Recommendations For Firefox for Android versions prior to 111, update to version 111 or later to resolve the issue. As a temporary workaround, consider confirming each launch of an external application to minimize the risk of exploitation. Restrict access to unpatched Android applications to reduce the risk of vulnerabilities being exploited through the Intent mechanism.

Correção

Incorrect Authorization

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-1443
ALT-PU-2023-1817
ALT-PU-2023-5202
BDU:2023-01805
CVE-2023-25749
OPENSUSE-SU-2024:12839-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2023:0728-1
SUSE-SU-2023:0763-1
SUSE-SU-2023:0835-1

Produtos afetados

Alt Linux
Astra Linux
Firefox For Android
Suse