First published: Tue Mar 19 2019(Updated: )
On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. Note: This issue only affects Android. Other operating systems are unaffected.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <66.0 | |
Google Android | ||
Mozilla Firefox | <66 | 66 |
All of | ||
Mozilla Firefox | <66.0 | |
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2019-9798 is high.
CVE-2019-9798 affects Android systems by allowing malicious third-party applications to execute a man-in-the-middle attack.
Firefox version up to 66 is affected by CVE-2019-9798.
To fix CVE-2019-9798, update Firefox to version 66 or higher.
The CWE ID of CVE-2019-9798 is 426.