Spoofing attack in Mozilla Firefox - CVE-2019-11695
Published: May 21, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of custom cursor. A remote attacker can define a custom cursor by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be used by a malicious site to trick users into clicking on permission prompts, doorhanger notifications, or other buttons inadvertently if the location is spoofed over the user interface.
Affected software
Arch Linux
firefox (Ubuntu package)
How to mitigate CVE-2019-11695
firefox (Ubuntu package) - addressed in versions 67.0+build2-0ubuntu0.16.04.1, 67.0+build2-0ubuntu0.18.04.1, 67.0+build2-0ubuntu0.18.10.1, 67.0+build2-0ubuntu0.19.04.1, 67.0.1+build1-0ubuntu0.16.04.1, 67.0.1+build1-0ubuntu0.18.04.1, 67.0.1+build1-0ubuntu0.18.10.1, 67.0.1+build1-0ubuntu0.19.04.1, 67.0.2+build2-0ubuntu0.16.04.1, 67.0.2+build2-0ubuntu0.18.04.1, 67.0.2+build2-0ubuntu0.18.10.1, 67.0.2+build2-0ubuntu0.19.04.1