PT-2015-1900 · Mozilla+3 · Firefox+3

Christoph Kerschbaumer

+1

·

Published

2015-08-11

·

Updated

2024-12-12

·

CVE-2015-4490

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 40.0
Description The issue arises from the nsCSPHostSrc::permits function in Mozilla Firefox, which does not implement Content Security Policy Level 2 exceptions for certain URL schemes during wildcard source-expression matching. This could make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior. The vulnerability might allow a remote attacker to inject arbitrary HTML code.
Recommendations For versions prior to 40.0, update to version 40.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive resources to minimize the risk of exploitation. Avoid using the vulnerable function nsCSPHostSrc::permits until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1704
ALT-PU-2016-1454
BDU:2015-11246
CVE-2015-4490
MGASA-2015-0414
OPENSUSE-SU-2015_1389-1
OPENSUSE-SU-2015_1390-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-2702-1
USN-2702-2
USN-2702-3

Affected Products

Alt Linux
Firefox
Suse
Ubuntu