Resource management error in Mozilla Firefox - CVE-2019-9806
Published: March 21, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to browser does not limit the number of authorization prompts for FTP transactions, displaying unlimited number of modal prompts that cannot be dismissed. A remote attacker can trick the victim to connect to a malicious crafted FTP server and perform denial of service attack against the browser.
Affected software
Arch Linux
firefox (Ubuntu package)
How to mitigate CVE-2019-9806
firefox (Ubuntu package) - addressed in versions 66.0.1+build1-0ubuntu0.14.04.1, 66.0.2+build1-0ubuntu0.14.04.1, 66.0.2+build1-0ubuntu0.16.04.1, 66.0.2+build1-0ubuntu0.18.04.1, 66.0.2+build1-0ubuntu0.18.10.1, 66.0.3+build1-0ubuntu0.14.04.1, 66.0.3+build1-0ubuntu0.16.04.1, 66.0.3+build1-0ubuntu0.18.04.1, 66.0.3+build1-0ubuntu0.18.10.1