Incorrect default permissions in Firefox ESR and Mozilla Firefox - CVE-2019-17009

 

Incorrect default permissions in Firefox ESR and Mozilla Firefox - CVE-2019-17009

Published: December 3, 2019


Vulnerability identifier: #VU23373
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17009
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to incorrect default permissions for status and log files files that are set by the updater service. A local user with access to the system can view contents of files and gain access to sensitive information.


Affected software

Firefox ESR
Mozilla Firefox
Arch Linux
Slackware Linux
Opensuse
Mozilla Thunderbird
firefox-esr (Alpine package)

How to mitigate CVE-2019-17009

Install updates from vendor's website.

Firefox ESR - update to 68.3.0
Mozilla Firefox - update to 71.0
Mozilla Thunderbird - update to 68.3.0
firefox-esr (Alpine package) - update to 68.3.0-r0

External References

Related Security Bulletins