Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Alarm raised over Mozilla VPN security flaw

  • August 7, 2023
Total
0
Shares
0
0
0


A cybersecurity researcher at SUSE has warned that the Mozilla VPN client for Linux holds a severe vulnerability that could allow threat actors to conduct a wide range of integrity violations.

Matthias Gerstner published an article on the Openwall security mailing list, in which he details a broken authentication check in Mozilla VPN client v2.14.1, released on May 30. 

Threat actors that discover the flaw can use it to set up their own arbitrary VPN, redirect network traffic to (potentially) malicious destinations, and break existing VPN setups.

Multiple integrity violations

Detailing the flaw, Gerstner says that SUSE’s engineers analyzed Mozilla’s VPN client and found that it “contains a privileged D-Bus service running as root and a Polkit policy.” Polkit is an authorization API for privileged programs, and as the program’s written now, Polkit is checking if the privileged Mozilla VPN D-Bus service is authorized to perform certain actions, instead of the user. 

“The impact is that arbitrary local users can configure arbitrary VPN setups using Mozilla VPN and thus possibly redirect network traffic to malicious parties, pretend that a secure VPN is present while it actually isn’t, perform a denial-of-service against an existing VPN connection or other integrity violations,” Gerstner said in his writeup.

SUSE disclosed its findings to Mozilla on May 4, but didn’t hear back from the company. Eight days later, on June 12, the company found the flaw disclosed in a GitHub pull request to the Mozilla VPN repository. 

“We asked upstream once more what their intentions are regarding coordinated disclosure but did not get a proper response,” Gerstner explained.

Three months later, as is the usual practice, SUSE publicly disclosed the flaw. It is now being tracked as CVE-2023-4104.

Mozilla is keeping quiet for now, with a representative telling The Register that more information should be available later today. 

Via: The Register


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

Secret trick installs Windows 11 without the bloatware – but Microsoft is looking to fix it

  • August 7, 2023
View Post
Next Article
  • Technology

One Model lands $41M to bring data science-powered insights to HR

  • August 7, 2023
View Post
You May Also Like
View Post
  • News

FTC Says Amazon Used These Tactics to Undermine Competition

  • September 26, 2023
View Post
  • News

Here Are the 2 Tactics Amazon Used to Undermine Competition, the F.T.C. Says

  • September 26, 2023
View Post
  • News

The laptop that weighs less than the Apple iPad Pro tablet has been refreshed — shame no one noticed

  • September 26, 2023
View Post
  • News

I was excited about the battery life on the Surface Laptop Studio 2… then I read the small print

  • September 26, 2023
View Post
  • News

Amazon to Invest Up to $4 Billion in A.I. Start-Up Anthropic

  • September 26, 2023
View Post
  • News

Top Apple Executive Defends Favoring Google on iPhones

  • September 26, 2023
View Post
  • News

CMF by Nothing’s new Buds Pro and Watch Pro look like affordable bargains

  • September 26, 2023
View Post
  • News

This super-dangerous Android malware has returned to target US shoppers and bankers

  • September 26, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.