PT-2019-4547 · Mozilla+2 · Firefox+2
Stephen Fewer
·
Published
2019-03-19
·
Updated
2024-12-12
·
CVE-2019-9802
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 66
Description
The issue is related to the lack of protection for internal data in the browser, which can be exploited by a remote attacker to gain access to confidential information. In the context of Firefox, if a Sandbox content process is compromised, it can initiate an FTP download. The downloaded data can then be passed to the Chrome process with an arbitrary file length supplied by an attacker, bypassing sandbox protections and potentially allowing for a memory read of adjacent data from the privileged Chrome process, which may include sensitive data.
Recommendations
For versions prior to 66, update to version 66 or later to resolve the issue. As a temporary workaround, consider restricting access to FTP downloads in the Sandbox content process to minimize the risk of exploitation.
Fix
Information Disclosure
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Firefox
Ubuntu