Spoofing attack in Mozilla Firefox - CVE-2019-11696
Published: May 21, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of .JNLP files that are not recognized as executable files. A remote attacker can trick the victim into downloading and running a malicious Java web start file and execute arbitrary Java code on the system.
Successful exploitation of the vulnerability requires that Java is installed on the system.
Affected software
Arch Linux
firefox (Ubuntu package)
How to mitigate CVE-2019-11696
firefox (Ubuntu package) - addressed in versions 67.0+build2-0ubuntu0.16.04.1, 67.0+build2-0ubuntu0.18.04.1, 67.0+build2-0ubuntu0.18.10.1, 67.0+build2-0ubuntu0.19.04.1, 67.0.1+build1-0ubuntu0.16.04.1, 67.0.1+build1-0ubuntu0.18.04.1, 67.0.1+build1-0ubuntu0.18.10.1, 67.0.1+build1-0ubuntu0.19.04.1, 67.0.2+build2-0ubuntu0.16.04.1, 67.0.2+build2-0ubuntu0.18.04.1, 67.0.2+build2-0ubuntu0.18.10.1, 67.0.2+build2-0ubuntu0.19.04.1