PT-2019-6365 · Mozilla+2 · Firefox+2

Emilio Cobos Álvarez

·

Published

2019-02-26

·

Updated

2024-12-11

·

CVE-2019-25136

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 70
Description The issue is related to a compromised child process that could inject XBL Bindings into privileged CSS rules, leading to arbitrary code execution and a sandbox escape. It is also described as a vulnerability in the web browser related to insufficient neutralization of special elements in a request, which could allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For versions prior to 70, update to version 70 or later to resolve the issue.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3087
ALT-PU-2020-1617
ALT-PU-2020-2408
ALT-PU-2020-2933
ALT-PU-2021-1368
BDU:2023-03818
CVE-2019-25136

Affected Products

Alt Linux
Astra Linux
Firefox