(Oracle Issues Fix for Oracle Linux) Mozilla Firefox PDF Viewer Same-Origin Bypass Lets Remote Users Obtain Potentially Sensitive Information on the Target System
|
SecurityTracker Alert ID: 1033221 |
SecurityTracker URL: http://securitytracker.com/id/1033221
|
CVE Reference:
CVE-2015-4495
(Links to External Site)
|
Updated: Aug 11 2015
|
Original Entry Date: Aug 8 2015
|
Impact:
Disclosure of system information, Disclosure of user information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): prior to 39.0.3
|
Description:
A vulnerability was reported in Mozilla Firefox. A remote user can obtain files from the target user's system.
A remote user can create specially crafted content that, when loaded by the target user, will bypass same-origin policy and inject arbitrary JavaScript into the built-in PDF Viewer in the local file context and gain access to files on the target user's system with the privileges of the target user.
This vulnerability is being actively exploited.
Cody Crews reported this vulnerability.
|
Impact:
A remote user can obtain files on the target user's system.
|
Solution:
Oracle has issued a fix.
The Oracle Linux advisory is available at:
http://linux.oracle.com/errata/ELSA-2015-1581.html
|
Vendor URL: linux.oracle.com/errata/ELSA-2015-1581.html (Links to External Site)
|
Cause:
Access control error
|
Underlying OS: Linux (Oracle)
|
Underlying OS Comments: 5, 6, 7
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Subject: [El-errata] ELSA-2015-1581 Important: Oracle Linux 6 firefox security update
|
Oracle Linux Security Advisory ELSA-2015-1581
http://linux.oracle.com/errata/ELSA-2015-1581.html
The following updated rpms for Oracle Linux 6 have been uploaded to the
Unbreakable Linux Network:
i386:
firefox-38.1.1-1.0.1.el6_7.i686.rpm
x86_64:
firefox-38.1.1-1.0.1.el6_7.i686.rpm
firefox-38.1.1-1.0.1.el6_7.x86_64.rpm
SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/firefox-38.1.1-1.0.1.el6_7.src.rpm
Description of changes:
[38.1.1-1.0.1]
- Add firefox-oracle-default-prefs.js and remove the corresponding Red
Hat one
- Force requirement of newer gdk-pixbuf2 to ensure a proper update (Todd
Vierling) [orabug 19847484]
[38.1.1-1]
- Update to 38.1.1 ESR
_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata
|
|