CVE-2019-9801Improper Input Validation in Mozilla Firefox

Severity
5.3MEDIUMNVD
EPSS
0.4%
top 41.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 26
Latest updateMay 24

Description

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified66
NVDmozilla/firefox< 66.0
CVEListV5mozilla/firefox_esrunspecified60.6

🔴Vulnerability Details

2
GHSA
GHSA-cr8h-fffv-pv55: Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on2022-05-24
OSV
CVE-2019-9801: Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on2019-04-26

📋Vendor Advisories

2
Red Hat
Mozilla: Windows programs that are not 'URL Handlers' are exposed to web content2019-03-20
Debian
CVE-2019-9801: firefox - Firefox will accept any registered Program ID as an external protocol handler an...2019

💬Community

1
Bugzilla
CVE-2019-9801 Mozilla: Windows programs that are not 'URL Handlers' are exposed to web content2019-03-20