A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary malicious preference values. Control of arbitrary preferences can lead to sufficient compromise such that it is generally equivalent to arbitrary code execution.<br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.
References
Link | Resource |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1617928 | Issue Tracking Permissions Required |
https://www.mozilla.org/security/advisories/mfsa2020-13/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2020-04-24 16:15
Updated : 2024-02-04 21:00
NVD link : CVE-2020-6828
Mitre link : CVE-2020-6828
CVE.ORG link : CVE-2020-6828
JSON object : View
Products Affected
- android
mozilla
- firefox_esr
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')