Incorrect permission assignment for critical resource in Mozilla Firefox - CVE-2019-11748

 

Incorrect permission assignment for critical resource in Mozilla Firefox - CVE-2019-11748

Published: September 3, 2019


Vulnerability identifier: #VU20827
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11748
CWE-ID: CWE-732
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to collect sensitive information.

The vulnerability exists due to the WebRTC in Firefox honors persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. A remote attacker that can create a specially crafted webpage that loads a trusted resource and trick the browser into allowing usage of microphone and camera resources.


Affected software

Mozilla Firefox
Firefox ESR
Arch Linux
Red Hat Enterprise Linux for x86_64
firefox (Ubuntu package)

How to mitigate CVE-2019-11748

Install updates from vendor's website.

Mozilla Firefox - update to 69.0
firefox (Ubuntu package) - addressed in versions 69.0+build2-0ubuntu0.16.04.4, 69.0+build2-0ubuntu0.18.04.1, 69.0+build2-0ubuntu0.19.04.1, 69.0.2+build1-0ubuntu0.16.04.1, 69.0.2+build1-0ubuntu0.18.04.1, 69.0.2+build1-0ubuntu0.19.04.1
Firefox ESR - update to 68.1.0

External References

Related Security Bulletins