Unprotected storage of credentials in Firefox ESR and Mozilla Firefox - CVE-2019-11733

 

Unprotected storage of credentials in Firefox ESR and Mozilla Firefox - CVE-2019-11733

Published: August 15, 2019


Vulnerability identifier: #VU20292
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11733
CWE-ID: CWE-256
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to a logical error in the way stored passwords are processed. A local user can access stored passwords in the 'Saved Logins' dialog, as locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without first entering the master password.


Affected software

Firefox ESR
Mozilla Firefox
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Slackware Linux
firefox (Ubuntu package)
firefox-esr (Alpine package)
firefox (Alpine package)

How to mitigate CVE-2019-11733

Install updates from vendor's website.

Firefox ESR - update to 68.0.2
Mozilla Firefox - update to 68.0.2
firefox (Ubuntu package) - addressed in versions 68.0.2+build1-0ubuntu0.16.04.1, 68.0.2+build1-0ubuntu0.18.04.1, 68.0.2+build1-0ubuntu0.19.04.1
firefox-esr (Alpine package) - update to 68.0.2-r0
firefox (Alpine package) - update to 68.0.2-r0

External References

Related Security Bulletins