CVE-2011-3079Improper Authentication in Mozilla Firefox

Severity
10.0CRITICALNVD
EPSS
0.4%
top 36.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1
Latest updateMay 14

Description

The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not properly validate messages, which has unspecified impact and attack vectors.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages12 packages

CVEListV5mozilla/firefoxunspecified65
NVDmozilla/firefox< 60.5.0+3
CVEListV5mozilla/firefox_esrunspecified60.5
NVDgoogle/chrome18.0.1025.166
CVEListV5mozilla/thunderbirdunspecified60.5

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 18.10, Enterprise Linux 7.6

🔴Vulnerability Details

5
GHSA
GHSA-493h-4p68-8587: The Inter-process Communication (IPC) implementation in Google Chrome before 182022-05-14
GHSA
GHSA-5g4g-56fq-mvwf: An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and2022-05-13
OSV
CVE-2018-18505: An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and2019-02-05
CVEList
CVE-2018-18505: An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and2019-02-05
CVEList
CVE-2011-3079: The Inter-process Communication (IPC) implementation in Google Chrome before 182012-05-01

📋Vendor Advisories

2
Red Hat
Mozilla: Privilege escalation through IPC channel messages2019-01-29
Debian
CVE-2018-18505: firefox - An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-...2018

💬Community

3
Bugzilla
CVE-2018-18505 Mozilla: Privilege escalation through IPC channel messages2019-01-29
Bugzilla
IPC channels created via Endpoint passing don't authenticate the client2018-10-10
Bugzilla
IPC Channel does not validate the listener.2014-10-22
CVE-2011-3079 — Improper Authentication in Mozilla | cvebase