PT-2019-4562 · Mozilla+2 · Firefox+2

Abdulrahman Alqabandi

·

Published

2019-05-21

·

Updated

2024-12-12

·

CVE-2019-11696

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 67
Description The issue concerns the handling of executable content for applications with the .JNLP extension, which are used for "Java web start" applications. These files are not treated as executable content for download prompts, even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally. Exploitation of this issue may allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For versions prior to 67, update to version 67 or later to resolve the issue. As a temporary workaround, consider disabling the execution of .JNLP files until a patch is applied. Restrict access to Java web start applications to minimize the risk of exploitation. Avoid launching executable binaries locally from download prompts to prevent potential attacks.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1941
ALT-PU-2019-2324
ALT-PU-2019-2479
ALT-PU-2019-2486
BDU:2020-00608
CVE-2019-11696
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3991-1
USN-3991-2
USN-3991-3

Affected Products

Alt Linux
Firefox
Ubuntu