PT-2019-4561 · Mozilla+2 · Firefox+2

Abdulrahman Alqabandi

·

Published

2019-05-21

·

Updated

2024-12-12

·

CVE-2019-11697

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 67
Description The issue is related to the installation of extensions. When the ALT and "a" keys are pressed during an extension installation prompt, the extension is installed without the usual delay, allowing users to accept or decline the installation. A malicious web page could exploit this by using spoofing to trick users into installing a malicious extension. This could potentially allow a remote attacker to impact data integrity.
Recommendations For versions prior to 67, update to version 67 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the ALT and "a" keys during extension installation prompts until the issue is resolved.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1941
ALT-PU-2019-2324
ALT-PU-2019-2479
ALT-PU-2019-2486
BDU:2020-00607
CVE-2019-11697
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3991-1
USN-3991-2
USN-3991-3

Affected Products

Alt Linux
Firefox
Ubuntu