Unprotected storage of credentials in Firefox ESR and Mozilla Firefox - CVE-2019-11733
Published: August 15, 2019
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to a logical error in the way stored passwords are processed. A local user can access stored passwords in the 'Saved Logins' dialog, as locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without first entering the master password.
Affected software
Mozilla Firefox
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Slackware Linux
firefox (Ubuntu package)
firefox-esr (Alpine package)
firefox (Alpine package)
How to mitigate CVE-2019-11733
Mozilla Firefox - update to 68.0.2
firefox (Ubuntu package) - addressed in versions 68.0.2+build1-0ubuntu0.16.04.1, 68.0.2+build1-0ubuntu0.18.04.1, 68.0.2+build1-0ubuntu0.19.04.1
firefox-esr (Alpine package) - update to 68.0.2-r0
firefox (Alpine package) - update to 68.0.2-r0
External References
Related Security Bulletins
- Unauthorized access to saved passwords in Mozilla Firefox and Firefox ESR
- Slackware Linux update for mozilla-firefox
- Arch Linux update for firefox
- Ubuntu update for Firefox
- Red Hat update for firefox
- Red Hat update for firefox
- Unprotected storage of credentials in firefox (Alpine package)
- Unprotected storage of credentials in firefox-esr (Alpine package)