Permissions, Privileges, and Access Controls in Mozilla Firefox - CVE-2019-11765
Published: October 23, 2019
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to the way Firefox handles messages to the parent process that trigger the 'Click to Play' permission prompt to be shown. A remote attacker can create a specially crafted web page and assign arbitrary permissions instead of 'Click to Play' permission, if the user accepted the permission request.
Affected software
Arch Linux
firefox (Ubuntu package)
firefox (Alpine package)
How to mitigate CVE-2019-11765
firefox (Ubuntu package) - addressed in versions 70.0+build2-0ubuntu0.16.04.1, 70.0+build2-0ubuntu0.18.04.1, 70.0+build2-0ubuntu0.19.04.1, 70.0+build2-0ubuntu0.19.10.1