+10 10 0
Published 8 years ago by microfracture with 0 Comments
  • Advisory Information

    Mozilla Foundation Security Advisory 2015-78

    Title: Same origin violation and local file stealing via PDF reader
    Impact: Critical
    Fixed in: Firefox 39.0.3 and Firefox ESR 38.1.1

    Security researcher Cody Crews reported on a way to violate the same origin policy and inject script into a non-privileged part of the built-in PDF Viewer. This would allow an attacker to read and steal sensitive local files on the victim's computer.

    Mozilla has received reports that an exploit based on this vulnerability has been found in the wild.

 

Join the Discussion

  • Auto Tier
  • All
  • 1
  • 2
  • 3
Post Comment

Here are some other snaps you may like...