Description
Mozilla Firefox before 42.0, when NTLM v1 is enabled for HTTP authentication, allows remote attackers to obtain sensitive hostname information by constructing a crafted web site that sends an NTLM request and reads the Workstation field of an NTLM type 3 message.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-4535 | Mozilla Firefox before 42.0, when NTLM v1 is enabled for HTTP authentication, allows remote attackers to obtain sensitive hostname information by constructing a crafted web site that sends an NTLM request and reads the Workstation field of an NTLM type 3 message. |
Ubuntu USN |
USN-2785-1 | Firefox vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-06T06:18:11.547Z
Reserved: 2015-06-10T00:00:00.000Z
Link: CVE-2015-4515
No data.
Status : Modified
Published: 2015-11-05T05:59:03.460
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-4515
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN