Lucene search

K
mozillaMozilla FoundationMFSA2015-52
HistoryMay 12, 2015 - 12:00 a.m.

Sensitive URL encoded information written to Android logcat — Mozilla

2015-05-1200:00:00
Mozilla Foundation
www.mozilla.org
14

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.001

Percentile

25.7%

Security researcher Muneaki Nishimura reported that Firefox for Android would write potentially sensitive data to the Android logcat that was encoded as part of logged URL strings. On Android 4.0 or earlier systems, logcat data is available to any application having READ_LOGS permission, leading to potential privacy violations.

Affected configurations

Vulners
Node
mozillafirefoxRange<38

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.001

Percentile

25.7%