CVE-2019-11757

Current Description

Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup' folder. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

Basic Data

PublishedSeptember 27, 2019
Last ModifiedOctober 05, 2019
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeCWE-20
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityMEDIUM
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactPARTIAL
CVSS 2 - Availability ImpactPARTIAL
CVSS 2 - Base Score6.8
SeverityMEDIUM
Exploitability Score8.6
Impact Score6.4
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • AND
    • OR - Configuration 1
      Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
      2.3ApplicationMozillaFirefox********69.0
      2.3ApplicationMozillaFirefox Esr********68.1.0
    • OR Running on/with:
      Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
      2.3OSMicrosoftWindows-*******

Vulnerable Software List

VendorProductVersions
Mozilla Firefox *
Mozilla Firefox Esr *

References

NameSourceURLTags
openSUSE-SU-2019:2251http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.htmlSUSE
openSUSE-SU-2019:2260http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.htmlSUSE
https://bugzilla.mozilla.org/show_bug.cgi?id=1572838https://bugzilla.mozilla.org/show_bug.cgi?id=1572838MISCIssue Tracking CVE-2004-0231 Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2019-25/https://www.mozilla.org/security/advisories/mfsa2019-25/CONFIRMVendor Advisory
https://www.mozilla.org/security/advisories/mfsa2019-26/https://www.mozilla.org/security/advisories/mfsa2019-26/CONFIRMVendor Advisory