Mozilla: IE protocols can be used to open known local files
Published Jul 23, 2019
6.5
MEDIUMCVSS 3.0
EPSS 1.37%
Description
A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.0.2.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<67.0.2
- Version
No data.
Red Hat Enterprise Linux 6
firefox
Not affected
Red Hat Enterprise Linux 6
thunderbird
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 7
thunderbird
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat Enterprise Linux 8
thunderbird
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 6 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability only affects versions of Firefox on the Windows operating system. Red Hat Enterprise Linux is not affected.
References (7)
- https://access.redhat.com/security/cve/CVE-2019-11702 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1552627 x_refsource_MISCIssue TrackingPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1721805 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-11702
- https://www.cve.org/CVERecord?id=CVE-2019-11702
- https://www.mozilla.org/en-US/security/advisories/mfsa2019-16/#CVE-2019-11702
- https://www.mozilla.org/security/advisories/mfsa2019-16/ x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-11702 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1552627 | x_refsource_MISCIssue TrackingPermissions RequiredVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1721805 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-11702 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-11702 | ||
| https://www.mozilla.org/en-US/security/advisories/mfsa2019-16/#CVE-2019-11702 | ||
| https://www.mozilla.org/security/advisories/mfsa2019-16/ | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.