CVE-2015-4495
published 2015-08-08CVE-2015-4495: The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin…
PriorityP188high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-06-15
Exploited in the wild
EPSS
67.33%
99.2th percentile
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | pdf.js | < pdf.js 1.1.366+dfsg-1 (bookworm) | pdf.js 1.1.366+dfsg-1 (bookworm) |
| mozilla | firefox | < 39.0.3 | 39.0.3 |
| mozilla | firefox | >= 0 < 39.0.3+build2-0ubuntu0.14.04.1 | 39.0.3+build2-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 38.0 < 38.1.1 | 38.1.1 |
| mozilla | firefox_os | < 2.2 | 2.2 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for use of __lookupSetter__ on the 'location' property of a cross-origin iframe's contentWindow, which is the native setter abuse at the core of this CVE. ↗
- →Detect repeated deep prototype chain traversal (__proto__ chained 6 levels) combined with PDF.js context, as used to escape the PDF.js sandbox. ↗
- →The in-the-wild payload targeted sensitive files on Windows, Linux, and macOS; monitor for Firefox processes accessing SSH key files or /etc/passwd following PDF rendering. ↗
- →Monitor for setInterval calls polling for a sandboxContext variable within a PDF.js rendering context, which is the exploit's mechanism to detect privilege escalation readiness. ↗
- ·Android versions of Firefox are not affected because they do not use the Mozilla PDF viewer (PDF.js). ↗
- ·Thunderbird packages on Red Hat Enterprise Linux 5, 6, and 7 are not affected by this vulnerability. ↗
- ·The vulnerability is scoped to the local PDF.js renderer; the XSS injection targets a non-privileged part of the built-in PDF viewer, not the full browser chrome. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox up to 39.0.2 PDF Reader information disclosure (USN-2707-1 / EDB-37772)
vuldb·2026-04-22·CVSS 8.8
CVE-2015-4495 [HIGH] Mozilla Firefox up to 39.0.2 PDF Reader information disclosure (USN-2707-1 / EDB-37772)
A vulnerability classified as critical was found in Mozilla Firefox up to 39.0.2. Affected is an unknown function of the component PDF Reader. The manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2015-4495. The attack may be launched remotely. Furthermore, there is an exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-cpx9-g67g-v8c5: The PDF reader in Mozilla Firefox before 39
ghsa_unreviewed·2022-05-14
CVE-2015-4495 [MEDIUM] CWE-200 GHSA-cpx9-g67g-v8c5: The PDF reader in Mozilla Firefox before 39
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
OSV
CVE-2015-4495: The PDF reader in Mozilla Firefox before 39
osv·2015-08-08·CVSS 8.8
CVE-2015-4495 [HIGH] CVE-2015-4495: The PDF reader in Mozilla Firefox before 39
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
OSV
firefox vulnerability
osv·2015-08-07·CVSS 8.8
CVE-2015-4495 [HIGH] firefox vulnerability
firefox vulnerability
Cody Crews discovered a way to violate the same-origin policy to inject
script in to a non-privileged part of the PDF viewer. If a user were
tricked in to opening a specially crafted website, an attacker could
exploit this to read sensitive information from local files.
(CVE-2015-4495)
VulnCheck
Mozilla Firefox Security Feature Bypass Vulnerability
vulncheck·2015·CVSS 8.8
CVE-2015-4495 [HIGH] CWE-200 Mozilla Firefox Security Feature Bypass Vulnerability
Mozilla Firefox Security Feature Bypass Vulnerability
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
Affected: Mozilla Firefox
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cve.org/CVERecord?id=CVE-2015-4495; https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/terror-exploit-kit-more-like-error-exploit-kit/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/996a7f0b0414
Remediation Due: 2022-06-15
CISA
Mozilla Firefox Security Feature Bypass Vulnerability
cisa·2022-05-25·CVSS 8.8
CVE-2015-4495 [HIGH] CWE-200 Mozilla Firefox Security Feature Bypass Vulnerability
Vulnerability: Mozilla Firefox Security Feature Bypass Vulnerability
Affected: Mozilla Firefox
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-4495
Remediation Due Date: 2022-06-15
Ubuntu
Firefox vulnerability
vendor_ubuntu·2015-08-07·CVSS 8.8
CVE-2015-4495 [HIGH] Firefox vulnerability
Title: Firefox vulnerability
Summary: Firefox could be made to expose sensitive information from local files.
Cody Crews discovered a way to violate the same-origin policy to inject
script in to a non-privileged part of the PDF viewer. If a user were
tricked in to opening a specially crafted website, an attacker could
exploit this to read sensitive information from local files.
(CVE-2015-4495)
Instructions: After a standard system update you need to restart Firefox to make
all the necessary changes.
Red Hat
Mozilla: Same origin violation and local file stealing via PDF reader (MFSA 2015-78)
vendor_redhat·2015-08-06·CVSS 8.8
CVE-2015-4495 [HIGH] Mozilla: Same origin violation and local file stealing via PDF reader (MFSA 2015-78)
Mozilla: Same origin violation and local file stealing via PDF reader (MFSA 2015-78)
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
A flaw was discovered in Mozilla Firefox that could be used to violate the same-origin policy and inject web script into a non-privileged part of the built-in PDF file viewer (PDF.js). An attacker could create a malicious web page that, when viewed by a victim, could steal arbitrary files (including private SSH keys, the /etc/passwd file, and other potentially sensitive files) from the system
Debian
CVE-2015-4495: pdf.js - The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1,...
vendor_debian·2015·CVSS 8.8
CVE-2015-4495 [HIGH] CVE-2015-4495: pdf.js - The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1,...
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
Scope: local
bookworm: resolved (fixed in 1.1.366+dfsg-1)
bullseye: resolved (fixed in 1.1.366+dfsg-1)
forky: resolved (fixed in 1.1.366+dfsg-1)
sid: resolved (fixed in 1.1.366+dfsg-1)
trixie: resolved (fixed in 1.1.366+dfsg-1)
Suricata
ET EXPLOIT Possible Firefox PDF.js Same-Origin-Bypass CVE-2015-4495 M2
suricata·2015-08-11·CVSS 8.8
CVE-2015-4495 [HIGH] ET EXPLOIT Possible Firefox PDF.js Same-Origin-Bypass CVE-2015-4495 M2
ET EXPLOIT Possible Firefox PDF.js Same-Origin-Bypass CVE-2015-4495 M2
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Firefox PDF.js Same-Origin-Bypass CVE-2015-4495 M2"; flow:established,to_client; file.data; content:"|77 69 6e 64 6f 77 73 5f 73 65 61 72 63 68 5f 61 6e 64 5f 75 70 6c 6f 61 64 5f 69 6e 5f 61 70 70 5f 64 61 74 61 5f 62 79 5f 64 69 73 6b|"; nocase; content:"|64 71 2e 61 77 61 69 74 41 6c 6c 28 63 61 6c 6c 62 61 63 6b 29|"; nocase; reference:url,nakedsecurity.sophos.com/2015/08/07/firefox-zero-day-hole-used-against-windows-and-linux-to-steal-passwords/; reference:cve,2015-4495; classtype:attempted-user; sid:2021606; rev:3; metadata:created_at 2015_08_11, cve CVE_2015_4495, confidence Medium, signature_severity Major, tag CISA_KEV, tag Descripti
Suricata
ET EXPLOIT Possible Firefox PDF.js Same-Origin-Bypass CVE-2015-4495 M1
suricata·2015-08-10·CVSS 8.8
CVE-2015-4495 [HIGH] ET EXPLOIT Possible Firefox PDF.js Same-Origin-Bypass CVE-2015-4495 M1
ET EXPLOIT Possible Firefox PDF.js Same-Origin-Bypass CVE-2015-4495 M1
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Firefox PDF.js Same-Origin-Bypass CVE-2015-4495 M1"; flow:established,to_client; file.data; content:"|76 69 65 77 2d 73 6f 75 72 63 65 3a|"; nocase; content:"|61 70 70 6c 69 63 61 74 69 6f 6e 2f 78 2d 6d 6f 7a 2d 70 6c 61 79 70 72 65 76 69 65 77 2d 70 64 66 6a 73|"; fast_pattern; nocase; content:"|73 61 6e 64 62 6f 78 43 6f 6e 74 65 78 74|"; nocase; content:"return "; pcre:"/\We[\s\x22\x27,+]*?v[\s\x22\x27,+]*?a[\s\x22\x27,+]*?l\W/"; reference:cve,2015-4495; classtype:attempted-user; sid:2021601; rev:4; metadata:created_at 2015_08_10, cve CVE_2015_4495, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Pr
Exploit-DB
Mozilla Firefox < 39.03 - 'pdf.js' Same Origin Policy
exploitdb·2015-08-15·CVSS 8.8
CVE-2015-4495 [HIGH] Mozilla Firefox < 39.03 - 'pdf.js' Same Origin Policy
Mozilla Firefox
CVE-2015-4495
Test
Run the index.html (Make sure the main.js is in the same directory) and we should be able to see the directory listing.
3. Solution
Upgrade to the latest firefox ( > 39.0.3)
*/
var start_timeout=2000;
var sandbox_context_i=null;
var DIR_CACHE={};
var FILE_CACHE={};
var hidden=true;
var my_win_id=null;
function start() {
i=document.getElementById("i");
i2=document.getElementById("i2");
if(typeof sandboxContext!=='undefined') {
clearInterval(intVal);
var os = navigator.platform;
if (os.search("Mac") > -1 || os.search("Linux") > -1) {
// NOTE: Replace the following root directory into any directory of your
// choice. Can make it an array and loop through it.
get_dir("/", function(data) {
// nothing to do here...
});
}
}
}
function parse_directo
Metasploit
Firefox PDF.js Browser File Theft
metasploit
Firefox PDF.js Browser File Theft
Firefox PDF.js Browser File Theft
This module abuses an XSS vulnerability in versions prior to Firefox 39.0.3, Firefox ESR 38.1.1, and Firefox OS 2.2 that allows arbitrary files to be stolen. The vulnerability occurs in the PDF.js component, which uses Javascript to render a PDF inside a frame with privileges to read local files. The in-the-wild malicious payloads searched for sensitive files on Windows, Linux, and OSX. Android versions are reported to be unaffected, as they do not use the Mozilla PDF viewer.
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1581.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-78.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/76249http://www.securitytracker.com/id/1033216http://www.ubuntu.com/usn/USN-2707-1https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/https://bugzilla.mozilla.org/show_bug.cgi?id=1178058https://bugzilla.mozilla.org/show_bug.cgi?id=1179262https://security.gentoo.org/glsa/201512-10https://www.exploit-db.com/exploits/37772/http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1581.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-78.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/76249http://www.securitytracker.com/id/1033216http://www.ubuntu.com/usn/USN-2707-1https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/https://bugzilla.mozilla.org/show_bug.cgi?id=1178058https://bugzilla.mozilla.org/show_bug.cgi?id=1179262https://security.gentoo.org/glsa/201512-10https://www.exploit-db.com/exploits/37772/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-4495
2015-08-08
Published
2022-05-25
Added to CISA KEV
Exploited in the wild