Bugzilla – Bug 940918
VUL-0: CVE-2015-4495: MozillaFirefox: MFSA-2015-78: 39.0.3/ ESR 38.1.1 same origin violation
Last modified: 2020-04-05 18:19:30 UTC
i think this was published on Blackhat. Working exploit to read files. https://www.mozilla.org/en-US/security/advisories/mfsa2015-78/
Security researcher Cody Crews reported on a way to violate the same origin policy and inject script into a non-privileged part of the built-in PDF Viewer. This would allow an attacker to read and steal sensitive local files on the victim's computer. Mozilla has received reports that an exploit based on this vulnerability has been found in the wild.
we could cover this with the firefox 40 update next tuesday
This is an autogenerated message for OBS integration: This bug (940918) was mentioned in https://build.opensuse.org/request/show/321234 13.2 / MozillaFirefox https://build.opensuse.org/request/show/321235 13.1 / MozillaFirefox https://build.opensuse.org/request/show/321236 Factory / MozillaFirefox
bugbot adjusting priority
An update workflow for this issue was started. This issue was rated as important. Please submit fixed packages until 2015-08-19. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/62259
SUSE-SU-2015:1379-1: An update that fixes one vulnerability is now available. Category: security (critical) Bug References: 940918 CVE References: CVE-2015-4495 Sources used: SUSE Linux Enterprise Software Development Kit 12 (src): MozillaFirefox-31.8.0esr-39.1, MozillaFirefox-31.8.0esr-40.1 SUSE Linux Enterprise Server 12 (src): MozillaFirefox-31.8.0esr-39.1, MozillaFirefox-31.8.0esr-40.1 SUSE Linux Enterprise Desktop 12 (src): MozillaFirefox-31.8.0esr-40.1
SUSE-SU-2015:1380-1: An update that fixes one vulnerability is now available. Category: security (critical) Bug References: 940918 CVE References: CVE-2015-4495 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): MozillaFirefox-31.8.0esr-0.13.2 SUSE Linux Enterprise Software Development Kit 11-SP3 (src): MozillaFirefox-31.8.0esr-0.13.2 SUSE Linux Enterprise Server for VMWare 11-SP3 (src): MozillaFirefox-31.8.0esr-0.13.2 SUSE Linux Enterprise Server 11-SP4 (src): MozillaFirefox-31.8.0esr-0.13.2 SUSE Linux Enterprise Server 11-SP3 (src): MozillaFirefox-31.8.0esr-0.13.2 SUSE Linux Enterprise Desktop 11-SP4 (src): MozillaFirefox-31.8.0esr-0.13.2 SUSE Linux Enterprise Desktop 11-SP3 (src): MozillaFirefox-31.8.0esr-0.13.2 SUSE Linux Enterprise Debuginfo 11-SP4 (src): MozillaFirefox-31.8.0esr-0.13.2 SUSE Linux Enterprise Debuginfo 11-SP3 (src): MozillaFirefox-31.8.0esr-0.13.2
openSUSE-SU-2015:1389-1: An update that fixes 21 vulnerabilities is now available. Category: security (important) Bug References: 940806,940918 CVE References: CVE-2015-4473,CVE-2015-4474,CVE-2015-4475,CVE-2015-4477,CVE-2015-4478,CVE-2015-4479,CVE-2015-4480,CVE-2015-4481,CVE-2015-4482,CVE-2015-4483,CVE-2015-4484,CVE-2015-4485,CVE-2015-4486,CVE-2015-4487,CVE-2015-4488,CVE-2015-4489,CVE-2015-4490,CVE-2015-4491,CVE-2015-4492,CVE-2015-4493,CVE-2015-4495 Sources used: openSUSE 13.2 (src): MozillaFirefox-40.0-38.1, MozillaFirefox-branding-openSUSE-40-4.3.1
openSUSE-SU-2015:1390-1: An update that fixes 21 vulnerabilities is now available. Category: security (important) Bug References: 940806,940918 CVE References: CVE-2015-4473,CVE-2015-4474,CVE-2015-4475,CVE-2015-4477,CVE-2015-4478,CVE-2015-4479,CVE-2015-4480,CVE-2015-4481,CVE-2015-4482,CVE-2015-4483,CVE-2015-4484,CVE-2015-4485,CVE-2015-4486,CVE-2015-4487,CVE-2015-4488,CVE-2015-4489,CVE-2015-4490,CVE-2015-4491,CVE-2015-4492,CVE-2015-4493,CVE-2015-4495 Sources used: openSUSE 13.1 (src): MozillaFirefox-40.0-82.1, MozillaFirefox-branding-openSUSE-40-2.3.1
SUSE-SU-2015:1449-1: An update that fixes 31 vulnerabilities is now available. Category: security (important) Bug References: 935033,935979,940806,940918 CVE References: CVE-2015-2721,CVE-2015-2722,CVE-2015-2724,CVE-2015-2725,CVE-2015-2726,CVE-2015-2728,CVE-2015-2730,CVE-2015-2733,CVE-2015-2734,CVE-2015-2735,CVE-2015-2736,CVE-2015-2737,CVE-2015-2738,CVE-2015-2739,CVE-2015-2740,CVE-2015-2743,CVE-2015-4000,CVE-2015-4473,CVE-2015-4474,CVE-2015-4475,CVE-2015-4478,CVE-2015-4479,CVE-2015-4484,CVE-2015-4485,CVE-2015-4486,CVE-2015-4487,CVE-2015-4488,CVE-2015-4489,CVE-2015-4491,CVE-2015-4492,CVE-2015-4495 Sources used: SUSE Linux Enterprise Server 11-SP2-LTSS (src): MozillaFirefox-38.2.0esr-10.1, MozillaFirefox-branding-SLED-31.0-0.5.7.11, firefox-gcc47-4.7.2_20130108-0.37.2, mozilla-nss-3.19.2.0-0.7.1 SUSE Linux Enterprise Server 11-SP1-LTSS (src): MozillaFirefox-38.2.0esr-10.1, MozillaFirefox-branding-SLED-31.0-0.5.7.11, firefox-gcc47-4.7.2_20130108-0.37.2, mozilla-nss-3.19.2.0-0.7.1 SUSE Linux Enterprise Debuginfo 11-SP2 (src): MozillaFirefox-38.2.0esr-10.1, mozilla-nss-3.19.2.0-0.7.1 SUSE Linux Enterprise Debuginfo 11-SP1 (src): MozillaFirefox-38.2.0esr-10.1, mozilla-nss-3.19.2.0-0.7.1
released