CVE-2019-11751
published 2019-09-27CVE-2019-11751: Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links…
PriorityP340high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.06%
60.8th percentile
Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup' folder. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| mozilla | firefox | < 69.0 | 69.0 |
| mozilla | firefox | >= unspecified < 69 | 69 |
| mozilla | firefox_esr | < 68.1.0 | 68.1.0 |
| mozilla | firefox_esr | >= unspecified < 68.1 | 68.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Malicious code execution through command line parameters
vendor_redhat·2019-09-03·CVSS 8.8
CVE-2019-11751 [HIGH] CWE-77 Mozilla: Malicious code execution through command line parameters
Mozilla: Malicious code execution through command line parameters
Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup' folder. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
Statement: This vulnerability only affected Firefox on the Windows operating system. Firefox on Red Hat Enterprise Linux is not affected.
Package: firefox (Red Hat Enterprise Linux 5) - Out of support scope
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7)
Debian
CVE-2019-11751: firefox - Logging-related command line parameters are not properly sanitized when Firefox ...
vendor_debian·2019·CVSS 8.8
CVE-2019-11751 [HIGH] CVE-2019-11751: firefox - Logging-related command line parameters are not properly sanitized when Firefox ...
Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup' folder. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
Scope: local
sid: resolved
GHSA
GHSA-mm6c-gvcp-4p56: Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on maliciou
ghsa_unreviewed·2022-05-24
CVE-2019-11751 [MEDIUM] GHSA-mm6c-gvcp-4p56: Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on maliciou
Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup' folder. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
OSV
CVE-2019-11751: Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on maliciou
osv·2019-09-27·CVSS 8.8
CVE-2019-11751 [HIGH] CVE-2019-11751: Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on maliciou
Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup' folder. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11751 Mozilla: Malicious code execution through command line parameters
bugzilla·2019-09-04·CVSS 8.8
CVE-2019-11751 [HIGH] CVE-2019-11751 Mozilla: Malicious code execution through command line parameters
CVE-2019-11751 Mozilla: Malicious code execution through command line parameters
Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup' folder.
*Note: this issue only affects Firefox on Windows operating systems.*
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-26/#CVE-2019-11751
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Ping Fan "Zetta" Ke (VXRL)
---
Statement:
This vulnerability only affected Firefox on the Windows operating system. Firefox on Red Hat Enterprise Linux is not affected.
---
This bug is now clo
Bugzilla
Firefox 69.0 is available
bugzilla·2019-09-03·CVSS 9.8
CVE-2019-11751 [CRITICAL] Firefox 69.0 is available
Firefox 69.0 is available
Description of problem:
Firefox 69.0 is available
Version-Release number of selected component (if applicable):
69.0
Additional info:
Release Notes: https://www.mozilla.org/en-US/firefox/69.0/releasenotes/
Security Advisory: https://www.mozilla.org/en-US/security/advisories/mfsa2019-25/
Security
- CVE-2019-11751: Malicious code execution through command line parameters
- CVE-2019-11746: Use-after-free while manipulating video
- CVE-2019-11744: XSS by breaking out of title and textarea elements using innerHTML
- CVE-2019-11742: Same-origin policy violation with SVG filters and canvas to steal cross-origin images
- CVE-2019-11736: File manipulation and privilege escalation in Mozilla Maintenance Service
- CVE-2019-11753: Privilege escalation with Mozilla Maint
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1572838https://www.mozilla.org/security/advisories/mfsa2019-25/https://www.mozilla.org/security/advisories/mfsa2019-26/http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00017.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1572838https://www.mozilla.org/security/advisories/mfsa2019-25/https://www.mozilla.org/security/advisories/mfsa2019-26/
2019-09-27
Published