4.3
CVSSv2

CVE-2013-0798

Published: 03/04/2013 Updated: 05/06/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Mozilla Firefox prior to 20.0 on Android uses world-writable and world-readable permissions for the app_tmp installation directory in the local filesystem, which allows malicious users to modify add-ons before installation via an application that leverages the time window during which app_tmp is used.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla firefox 19.0.1

mozilla firefox 19.0

Vendor Advisories

Mozilla Foundation Security Advisory 2013-33 World read and write access to app_tmp directory on Android Announced April 2, 2013 Reporter Shuichiro Suzuki Impact Moderate Products Firefox Fixed in ...