Incorrect permission assignment for critical resource in Mozilla Firefox - CVE-2019-11748
Published: September 3, 2019
Vulnerability details
The vulnerability allows a remote attacker to collect sensitive information.
The vulnerability exists due to the WebRTC in Firefox honors persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. A remote attacker that can create a specially crafted webpage that loads a trusted resource and trick the browser into allowing usage of microphone and camera resources.
Affected software
Firefox ESR
Arch Linux
Red Hat Enterprise Linux for x86_64
firefox (Ubuntu package)
How to mitigate CVE-2019-11748
firefox (Ubuntu package) - addressed in versions 69.0+build2-0ubuntu0.16.04.4, 69.0+build2-0ubuntu0.18.04.1, 69.0+build2-0ubuntu0.19.04.1, 69.0.2+build1-0ubuntu0.16.04.1, 69.0.2+build1-0ubuntu0.18.04.1, 69.0.2+build1-0ubuntu0.19.04.1
Firefox ESR - update to 68.1.0