Incorrect default permissions in Firefox ESR and Mozilla Firefox - CVE-2019-17009
Published: December 3, 2019
Vulnerability identifier: #VU23373
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17009
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for status and log files files that are set by the updater service. A local user with access to the system can view contents of files and gain access to sensitive information.
Affected software
Firefox ESR
Mozilla Firefox
Arch Linux
Slackware Linux
Opensuse
Mozilla Thunderbird
firefox-esr (Alpine package)
Mozilla Firefox
Arch Linux
Slackware Linux
Opensuse
Mozilla Thunderbird
firefox-esr (Alpine package)
How to mitigate CVE-2019-17009
Install updates from vendor's website.
Firefox ESR - update to 68.3.0
Mozilla Firefox - update to 71.0
Mozilla Thunderbird - update to 68.3.0
firefox-esr (Alpine package) - update to 68.3.0-r0
Mozilla Firefox - update to 71.0
Mozilla Thunderbird - update to 68.3.0
firefox-esr (Alpine package) - update to 68.3.0-r0
External References
Related Security Bulletins
- Arch Linux update for firefox
- Slackware Linux update for mozilla-firefox
- Multiple vulnerabilities in Mozilla Firefox and Firefox ESR
- Multiple vulnerabilities in Mozilla Thunderbird
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaThunderbird
- Incorrect default permissions in firefox-esr (Alpine package)