#VU20292 Unprotected storage of credentials in Firefox ESR and Mozilla Firefox


Published: 2019-08-15

Vulnerability identifier: #VU20292

Vulnerability risk: Low

CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-11733

CWE-ID: CWE-256

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Firefox ESR
Client/Desktop applications / Web browsers
Mozilla Firefox
Client/Desktop applications / Web browsers

Vendor: Mozilla

Description

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to a logical error in the way stored passwords are processed. A local user can access stored passwords in the 'Saved Logins' dialog, as locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without first entering the master password.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Firefox ESR: 68.0 - 68.0.1, 60.0 - 60.8.0

Mozilla Firefox: 61.0 - 68.0.1


External links
http://www.mozilla.org/en-US/security/advisories/mfsa2019-24/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability