First published: Tue May 21 2019(Updated: )
A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result in user confusion of which site is currently loaded for spoofing attacks.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <67 | 67 |
Mozilla Firefox | <67.0 | |
debian/firefox | 132.0.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-11699 is a vulnerability that allows a malicious page to briefly cause the wrong name to be highlighted as the domain name in the address bar during page navigations, potentially leading to user confusion and spoofing attacks.
Mozilla Firefox versions prior to 67 are affected by CVE-2019-11699.
CVE-2019-11699 has a severity score of 6.5, categorizing it as a medium-severity vulnerability.
To fix CVE-2019-11699, update your Mozilla Firefox browser to version 67 or later.
You can find more information about CVE-2019-11699 in the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1528939), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2019-13/)