CVE-2015-4498: High severity firefox vulnerability
The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4498?
CVE-2015-4498 has a medium severity rating, as it allows remote attackers to bypass user-confirmation requirements.
How do I fix CVE-2015-4498?
To fix CVE-2015-4498, update Mozilla Firefox to version 40.0.3 or later, or Firefox ESR to version 38.2.1 or later.
What versions of Mozilla Firefox are affected by CVE-2015-4498?
CVE-2015-4498 affects Mozilla Firefox versions prior to 40.0.3 and Firefox ESR versions prior to 38.2.1.
What types of attacks can exploit CVE-2015-4498?
CVE-2015-4498 can be exploited by using crafted data URLs to perform actions without the user's confirmation.
Is user confirmation required for add-on installations in Firefox versions affected by CVE-2015-4498?
No, in the affected Firefox versions, attackers can bypass the intended user-confirmation requirement for add-on installations.