Vulnerability CVE-2019-11730


Published: 2019-07-23

Description:
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

Type:

CWE-200

(Information Exposure)

Vendor: Mozilla
Product: Thunderbird 
Version:
9.0.1
9.0
8.0
7.0.1
7.0
60.7.1
60.7.0
60.6.1
60.6.0
60.5.1
60.5.0
60.4.0
60.3.3
60.3.2
60.3.1
60.3.0
60.2.1
60.0
6.0.2
6.0.1
6.0
59.0
58.0
57.0
56.0
55.0
See more versions on NVD
Product: Firefox 
Version:
9.0.1
9.0
8.0.1
8.0
7.0.1
7.0
67.0.2
66.0.3
66.0.2
66.0.1
66.0
65.0
64.0.2
64.0
63.0.3
63.0.1
63.0
62.0.3
62.0.2
62.0
61.0.2
61.0.1
61.0
60.7.3
60.6.1
60.5.0
60.4.0
60.3.0
60.2.2
60.2.1
60.2.0
60.1.0
60.0.2
60.0.1
60.0
6.0.2
6.0.1
6.0
59.0.3
59.0.2
59.0.1
59.0
58.0.2
58.0.1
58.0
57.0.4
57.0.3
57.0.2
57.0.1
57.0
56.0.2
56.0.1
56.0
55.0.3
55.0.2
55.0.1
55.0
54.0.1
54.0
See more versions on NVD
Product: Firefox esr 
Version:
60.7.1
60.7.0
60.6.1
60.6.0
60.5.0
60.4.0
60.3.0
60.2.2
60.2.0
60.1.0
60.0
See more versions on NVD
Vendor: Debian
Product: Debian linux 
Version: 8.0;

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.html
https://bugzilla.mozilla.org/show_bug.cgi?id=1558299
https://lists.debian.org/debian-lts-announce/2019/08/msg00001.html
https://lists.debian.org/debian-lts-announce/2019/08/msg00002.html
https://security.gentoo.org/glsa/201908-12
https://security.gentoo.org/glsa/201908-20
https://www.mozilla.org/security/advisories/mfsa2019-21/
https://www.mozilla.org/security/advisories/mfsa2019-22/
https://www.mozilla.org/security/advisories/mfsa2019-23/

Related CVE
CVE-2019-18397
A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user...
CVE-2012-4385
letodms 3.3.6 has CSRF via change password
CVE-2012-4384
letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar
CVE-2011-1588
Thunar 1.2 through 1.2.1 could crash when copy and pasting a file name with % format characters due to a format string error.
CVE-2011-1488
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service ...
CVE-2011-1136
In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.
CVE-2011-1070
v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mode and potentially other consequences.
CVE-2011-0544
phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.

Copyright 2019, cxsecurity.com

 

Back to Top