Lucene search

K
ubuntucveUbuntu.comUB:CVE-2019-11733
HistoryAug 16, 2019 - 12:00 a.m.

CVE-2019-11733

2019-08-1600:00:00
ubuntu.com
ubuntu.com
10

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

68.8%

When a master password is set, it is required to be entered again before
stored passwords can be accessed in the ‘Saved Logins’ dialog. It was found
that locally stored passwords can be copied to the clipboard thorough the
‘copy password’ context menu item without re-entering the master password
if the master password had been previously entered in the same session,
allowing for potential theft of stored passwords. This vulnerability
affects Firefox < 68.0.2 and Firefox ESR < 68.0.2.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchfirefox< 68.0.2+build1-0ubuntu0.18.04.1UNKNOWN
ubuntu19.04noarchfirefox< 68.0.2+build1-0ubuntu0.19.04.1UNKNOWN
ubuntu16.04noarchfirefox< 68.0.2+build1-0ubuntu0.16.04.1UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

68.8%