PT-2019-16005 · Midori · Midori Browser
Gareth Heyes
·
Published
2019-12-20
·
Updated
2020-01-14
·
CVE-2019-19916
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Midori Browser version 0.5.11
Description
The issue arises from incorrect application of Content Security Policy (CSP) to multipart content sent with the multipart/x-mixed-replace MIME type. This could lead to script execution in areas where CSP should have blocked it, potentially allowing cross-site scripting (XSS) and other attacks when the product renders the content as HTML. The problem also involves consideration of the polyglot case, where a file can be both a valid image (e.g., GIF) and valid JavaScript.
Recommendations
For Midori Browser version 0.5.11, consider updating to a version where this issue is resolved, as the current version does not correctly apply CSP to all parts of multipart content. As a temporary workaround, consider restricting the rendering of multipart content to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Midori Browser