Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 68.7%; technical severity is CVSS 8.8.
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
Who should care
- Teams operating Ubuntu Linux, Firefox, Firefox Os +12 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Ubuntu Linux, Firefox, Firefox Os +12 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Oracle Security patch Bulletinapr2016 2952098
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Advisory
- Mozilla Security advisory Mfsa2015 78Mozilla · Vendor sourceVerification pending ↗
- Mozilla Security advisory Firefox Exploit Found In The WildMozilla · Vendor sourceVerification pending ↗
- Mozilla Security advisory Show Bug.cgiMozilla · Vendor sourceVerification pending ↗
- Mozilla Security advisory Show Bug.cgiMozilla · Vendor sourceVerification pending ↗
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE
- CWE-200
- Affected versions
- Canonical Ubuntu Linux (Version 12.04 | Version 14.04 | Version 15.04); Mozilla Firefox (End Excluding 39.0.3 | Start Including 38.0, End Excluding 38.1.1); Mozilla Firefox Os (End Excluding 2.2); Opensuse Opensuse (Version 13.1 | Version 13.2); Oracle Solaris (Version 11.3); Redhat Enterprise Linux Desktop (Version 5.0 | Version 6.0 | Version 7.0); Redhat Enterprise Linux Eus (Version 6.7 | Version 7.1 | Version 7.2 | Version 7.3); Redhat Enterprise Linux Server (Version 5.0 | Version 6.0 | Version 7.0)
- Fixed versions
- Mozilla Firefox (Fixed from 39.0.3, 38.1.1); Mozilla Firefox Os (Fixed from 2.2)
- Published
- 7 August 2015
- Attack vector
- Network
- Privileges required
- None
- User interaction
- Required
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 68.7%
- Signal calculated at 80
External references
- Red Hat Third-party advisory RHSA 2015 1581
- Ubuntu Third-party advisory USN-2707-1
- CISA Government advisory CVE-2015-4495
- Lists Opensuse Third-party advisory Msg00009
- Lists Opensuse Third-party advisory Msg00010
- Lists Opensuse Third-party advisory Msg00014
- Lists Opensuse Third-party advisory Msg00015
- Lists Opensuse Third-party advisory Msg00021
- Lists Opensuse Third-party advisory Msg00016
- Securityfocus Third-party advisory
- Securitytracker Third-party advisory 1033216
- Security Gentoo Third-party advisory 201512 10