Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-11749

Опубликовано: 27 сент. 2019
Источник: debian
EPSS Низкий

Описание

A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting of users. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed69.0-1package
firefox-esrfixed68.1.0esr-1package
firefox-esrnot-affectedbusterpackage
firefox-esrnot-affectedstretchpackage
firefox-esrnot-affectedjessiepackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-25/#CVE-2019-11749

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-26/#CVE-2019-11749

EPSS

Процентиль: 58%
0.00369
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 6 лет назад

A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting of users. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

CVSS3: 4.3
redhat
около 6 лет назад

A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting of users. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

CVSS3: 4.3
nvd
около 6 лет назад

A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting of users. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

github
больше 3 лет назад

A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting of users. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

CVSS3: 6.5
fstec
около 6 лет назад

Уязвимость браузера Firefox, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к информации

EPSS

Процентиль: 58%
0.00369
Низкий