Resource management error in Mozilla Firefox - CVE-2019-9809

 

Resource management error in Mozilla Firefox - CVE-2019-9809

Published: March 21, 2019


Vulnerability identifier: #VU18046
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9809
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect processing of modal alert messages sent by FTP server. A remote attacker can trick the victim to connect to a malicious FTP server and trigger a series of modal alert messages for these resources through invalid credentials or locations, resulting in denial of service attack

Affected software

Mozilla Firefox
Arch Linux
firefox (Ubuntu package)

How to mitigate CVE-2019-9809

Install updates from vendor's website.

Mozilla Firefox - update to 66.0
firefox (Ubuntu package) - addressed in versions 66.0.1+build1-0ubuntu0.14.04.1, 66.0.2+build1-0ubuntu0.14.04.1, 66.0.2+build1-0ubuntu0.16.04.1, 66.0.2+build1-0ubuntu0.18.04.1, 66.0.2+build1-0ubuntu0.18.10.1, 66.0.3+build1-0ubuntu0.14.04.1, 66.0.3+build1-0ubuntu0.16.04.1, 66.0.3+build1-0ubuntu0.18.04.1, 66.0.3+build1-0ubuntu0.18.10.1

External References

Related Security Bulletins