SB2019090646 - Cross-site scripting in firefox-esr (Alpine package)
Published: September 6, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cross-site scripting (CVE-ID: CVE-2019-11744)
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data within
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=df118d5706ba2d60b54d1285b0c2544abd2dc984
- https://git.alpinelinux.org/aports/commit/?id=ebf9184f5bbef1f9faab710ffb48bb36b5bae10e
- https://git.alpinelinux.org/aports/commit/?id=e5cf7735a9421cc3029ffa0ffda33135ab64ac6a
- https://git.alpinelinux.org/aports/commit/?id=6f6dc3727e020934d6a5a3d10fe2b591bd4c305a
- https://git.alpinelinux.org/aports/commit/?id=0022d15ae85827001bd50d87a374fd81eb56167b