Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-4495

Опубликовано: 06 авг. 2015
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

A flaw was discovered in Mozilla Firefox that could be used to violate the same-origin policy and inject web script into a non-privileged part of the built-in PDF file viewer (PDF.js). An attacker could create a malicious web page that, when viewed by a victim, could steal arbitrary files (including private SSH keys, the /etc/passwd file, and other potentially sensitive files) from the system running Firefox.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5thunderbirdNot affected
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 7thunderbirdNot affected
Red Hat Enterprise Linux 5firefoxFixedRHSA-2015:158107.08.2015
Red Hat Enterprise Linux 6firefoxFixedRHSA-2015:158107.08.2015
Red Hat Enterprise Linux 7firefoxFixedRHSA-2015:158107.08.2015

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1251318Mozilla: Same origin violation and local file stealing via PDF reader (MFSA 2015-78)

EPSS

Процентиль: 99%
0.69924
Средний

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 10 лет назад

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

CVSS3: 8.8
nvd
около 10 лет назад

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

CVSS3: 8.8
debian
около 10 лет назад

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x befo ...

suse-cvrf
около 10 лет назад

Security update for MozillaFirefox

suse-cvrf
около 10 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 99%
0.69924
Средний

4.3 Medium

CVSS2