Bug 1151260 - (CVE-2019-11754) VUL-0: CVE-2019-11754: MozillaFirefox: Pointer Lock is enabled with no user notification
(CVE-2019-11754)
VUL-0: CVE-2019-11754: MozillaFirefox: Pointer Lock is enabled with no user n...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Charles Robertson
Security Team bot
https://smash.suse.de/issue/242915/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-09-19 06:29 UTC by Alexander Bergmann
Modified: 2020-04-17 15:50 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2019-09-19 06:29:31 UTC
rh#1753448

When the pointer lock is enabled by a website though `requestPointerLock()`, no user notification is given. This could allow a malicious website to hijack the mouse pointer and confuse users.

External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-31/#CVE-2019-11754

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1753448
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-11754
Comment 1 Alexander Bergmann 2019-09-19 06:29:49 UTC
This only affects openSUSE:Factory.
Comment 2 Marcus Meissner 2020-04-17 15:50:47 UTC
was fixed I would assume.