Oval Definition:oval:com.ubuntu.bionic:def:20199803000
Revision Date:2019-04-26Version:1
Title:CVE-2019-9803 on Ubuntu 18.04 LTS (bionic) - medium.
Description:The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than perform the security upgrade requested by the CSP in some circumstances, allowing for potential man-in-the-middle attacks on the linked resources. This vulnerability affects Firefox < 66.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-9803
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND Package Information
  • The 'firefox' package in bionic was vulnerable but has been fixed (note: '66.0+build3-0ubuntu0.18.04.1').
  • OR The vulnerability of the 'mozjs38' package in bionic is not known (status: 'needs-triage'). It is pending evaluation.
  • OR The vulnerability of the 'mozjs52' package in bionic is not known (status: 'needs-triage'). It is pending evaluation.
  • BACK