Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-13075

Опубликовано: 30 июн. 2019
Источник: debian
EPSS Низкий

Описание

Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefox-esrfixed68.2.0esr-1package
firefoxfixed68.0-1package

Примечания

  • https://hackerone.com/reports/588239

  • https://trac.torproject.org/projects/tor/ticket/30657

  • This affects Firefox, but it's not a security issue in Firefox by itself

EPSS

Процентиль: 35%
0.00146
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.

CVSS3: 5.3
nvd
больше 6 лет назад

Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.

CVSS3: 5.3
github
больше 3 лет назад

Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.

CVSS3: 5.3
fstec
больше 6 лет назад

Уязвимость веб-браузера Tor, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 35%
0.00146
Низкий