CVE-2019-11697
Published: 21 May 2019
If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation. A malicious web page could use this with spoofing on the page to trick users into installing a malicious extension. This vulnerability affects Firefox < 67.
Priority
CVSS 3 base score: 6.5
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
bionic |
Released
(67.0+build2-0ubuntu0.18.04.1)
|
cosmic |
Released
(67.0+build2-0ubuntu0.18.10.1)
|
|
disco |
Released
(67.0+build2-0ubuntu0.19.04.1)
|
|
eoan |
Released
(67.0+build2-0ubuntu1)
|
|
focal |
Released
(67.0+build2-0ubuntu1)
|
|
groovy |
Released
(67.0+build2-0ubuntu1)
|
|
hirsute |
Released
(67.0+build2-0ubuntu1)
|
|
impish |
Released
(67.0+build2-0ubuntu1)
|
|
jammy |
Released
(67.0+build2-0ubuntu1)
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Released
(67.0)
|
|
xenial |
Released
(67.0+build2-0ubuntu0.16.04.1)
|
|
mozjs38 Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Does not exist
|
|
mozjs52 Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
cosmic |
Ignored
(reached end-of-life)
|
|
disco |
Ignored
(reached end-of-life)
|
|
eoan |
Ignored
(reached end-of-life)
|
|
focal |
Needs triage
|
|
groovy |
Ignored
(reached end-of-life)
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Does not exist
|
|
mozjs60 Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
cosmic |
Ignored
(reached end-of-life)
|
|
disco |
Ignored
(reached end-of-life)
|
|
eoan |
Ignored
(reached end-of-life)
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Does not exist
|
Notes
Author | Note |
---|---|
tyhicks | mozjs contains a copy of the SpiderMonkey JavaScript engine |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11697
- https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/#CVE-2019-11697
- https://ubuntu.com/security/notices/USN-3991-1
- NVD
- Launchpad
- Debian