Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-12383

Опубликовано: 28 мая 2019
Источник: debian

Описание

Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's UI locale by measuring a button width, even if the user has a "Don't send my language" setting.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefox-esrunfixedpackage
firefoxunfixedpackage

Примечания

  • https://gitweb.torproject.org/tor-browser.git/commit/?id=cbb04b72c68272c2de42f157d40cd7d29a6b7b55

  • https://hackerone.com/reports/282748

  • https://trac.torproject.org/projects/tor/ticket/24056

  • This affects Firefox, but it's not a security issue in Firefox by itself

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 6 лет назад

Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's UI locale by measuring a button width, even if the user has a "Don't send my language" setting.

CVSS3: 4.3
nvd
больше 6 лет назад

Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's UI locale by measuring a button width, even if the user has a "Don't send my language" setting.

CVSS3: 4.3
github
больше 3 лет назад

Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's UI locale by measuring a button width, even if the user has a "Don't send my language" setting.