Permissions, Privileges, and Access Controls in firefox-esr (Alpine package)



Published: 2019-03-23
Risk High
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2019-9801
CWE-ID CWE-264
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
firefox-esr (Alpine package)
Operating systems & Components / Operating system package or component

Vendor Alpine Linux Development Team

Security Bulletin

This security bulletin contains one high risk vulnerability.

1) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU18039

Risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-9801

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to Firefox accepts any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. A remote attacker can trick the victim to open a specially crafted link and execute an arbitrary application on the system with privileges of the current user.

Note: this vulnerability affects Windows operating system only.

Mitigation

Install update from vendor's website.

Vulnerable software versions

firefox-esr (Alpine package): 60.4.0-r0 - 60.5.2-r0

External links

http://git.alpinelinux.org/aports/commit/?id=5f4478599688e562154c7fc319b29c46f79083bf
http://git.alpinelinux.org/aports/commit/?id=985780d336a595bbba269e8d1c32715d70dbee68


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###