When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leading to arbitrary code execution. *Note: This issue only affects the Windows operating system; other operating systems are unaffected.* This vulnerability affects Firefox < 78.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2020-24/ | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1642400 | issue tracking vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00027.html | vendor advisory broken link |
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00049.html | vendor advisory broken link |