CVE-2019-9798: High severity firefox vulnerability
On Android systems, Firefox can load a library from APITRACELIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. Note: This issue only affects Android. Other operating systems are unaffected.
Other sources
On Android systems, Firefox can load a library from APITRACELIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. Note: This issue only affects Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 66.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2019-9798?
The severity of CVE-2019-9798 is high.
How does CVE-2019-9798 affect Android systems?
CVE-2019-9798 affects Android systems by allowing malicious third-party applications to execute a man-in-the-middle attack.
Which version of Firefox is affected by CVE-2019-9798?
Firefox version up to 66 is affected by CVE-2019-9798.
How can I fix CVE-2019-9798?
To fix CVE-2019-9798, update Firefox to version 66 or higher.
What is the CWE ID of CVE-2019-9798?
The CWE ID of CVE-2019-9798 is 426.