Mozilla Foundation Security Advisory 2015-69

Privilege escalation through internal workers

Announced
July 2, 2015
Reporter
Jonas Jenwald
Impact
High
Products
Firefox, Firefox ESR, Firefox OS
Fixed in
  • Firefox 39
  • Firefox ESR 31.8
  • Firefox ESR 38.1
  • Firefox OS 2.2

Description

Mozilla community member Jonas Jenwald reported broken behavior in Mozilla's PDF.js PDF file viewer which led to the discovery that internal Workers were incorrectly executed with high privilege. If this flaw were combined with a separate vulnerability allowing for same-origin policy violation, it could be used to run arbitrary code.

References