PT-2019-4541 · Mozilla+2 · Firefox+2
Hanno Böck
+1
·
Published
2019-03-19
·
Updated
2024-12-12
·
CVE-2019-9809
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 66
Description
The issue is related to the management of resources when the source for resources on a page is through an FTP connection. It is possible to trigger a series of modal alert messages for these resources through invalid credentials or locations, leading to a denial of service attack. These messages cannot be immediately dismissed.
Recommendations
For versions prior to 66, update to version 66 or later to resolve the issue. As a temporary workaround, consider avoiding the use of FTP connections for resource sourcing until the update is applied. Restrict access to FTP resources to minimize the risk of exploitation.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox
Ubuntu