PT-2015-2643 · Mozilla+3 · Firefox+3
Tim Brown
·
Published
2015-11-03
·
Updated
2024-12-12
·
CVE-2015-4515
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 42.0
Description
The issue is related to a lack of protection for service data in Mozilla Firefox. It allows a remote attacker to obtain sensitive hostname information by constructing a crafted web site that sends an NTLM request and reads the Workstation field of an NTLM type 3 message. This can be done when NTLM v1 is enabled for HTTP authentication.
Recommendations
For versions prior to 42.0, update to version 42.0 or later to resolve the issue. As a temporary workaround, consider disabling NTLM v1 for HTTP authentication to minimize the risk of exploitation. Restrict access to sensitive information and avoid using NTLM v1 for authentication until the issue is resolved.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox
Suse
Ubuntu