ASA-2019-00448 – Mozilla Firefox: Port scanning through Alt-Svc header


Allele Security Alert

ASA-2019-00448

Identifier(s)

ASA-2019-00448, CVE-2019-11728, MFSA2019-21

Title

Port scanning through Alt-Svc header

Vendor(s)

Mozilla Foundation

Product(s)

Mozilla Firefox

Affected version(s)

Mozilla Firefox version before 68

Fixed version(s)

Mozilla Firefox version 68

Proof of concept

Unknown

Description

The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded.

Technical details

Unknown

Credits

Trishita Tiwari and Ari Trachtenberg

Reference(s)

Mozilla Foundation Security Advisory 2019-21
https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/#CVE-2019-11728

Bug 1552993
https://bugzilla.mozilla.org/show_bug.cgi?id=1552993

CVE-2019-11728
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11728

CVE-2019-11728
https://nvd.nist.gov/vuln/detail/CVE-2019-11728

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: July 18, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.