Spoofing attack in Mozilla Firefox - CVE-2019-11697
Published: May 22, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of key combinations. A remote attacker can trick the victim to press ALT and "a" keystrokes on keyboard that delays extension installation prompt. A remote attacker can spoof the page and trick the victim to install malicious extension.
Affected software
Arch Linux
firefox (Ubuntu package)
How to mitigate CVE-2019-11697
firefox (Ubuntu package) - addressed in versions 67.0+build2-0ubuntu0.16.04.1, 67.0+build2-0ubuntu0.18.04.1, 67.0+build2-0ubuntu0.18.10.1, 67.0+build2-0ubuntu0.19.04.1, 67.0.1+build1-0ubuntu0.16.04.1, 67.0.1+build1-0ubuntu0.18.04.1, 67.0.1+build1-0ubuntu0.18.10.1, 67.0.1+build1-0ubuntu0.19.04.1, 67.0.2+build2-0ubuntu0.16.04.1, 67.0.2+build2-0ubuntu0.18.04.1, 67.0.2+build2-0ubuntu0.18.10.1, 67.0.2+build2-0ubuntu0.19.04.1