ArchLinux: 201908-11: firefox: information disclosure
Summary
An issue has been found in Firefox before 68.0.2. When a master password is set, it is required to be entered before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard through the 'copy password' context menu item without first entering the master password, allowing for potential theft of stored passwords.
Resolution
Upgrade to 68.0.2-1.
# pacman -Syu "firefox>=68.0.2-1"
The problem has been fixed upstream in version 68.0.2.
References
https://www.mozilla.org/en-US/security/advisories/mfsa2019-24/ https://www.mozilla.org/en-US/security/advisories/mfsa2019-24/#CVE-2019-11733 https://bugzilla.mozilla.org/show_bug.cgi?id=1565780 https://security.archlinux.org/CVE-2019-11733
Workaround
None.