SB2020083012 - Spoofing attack in firefox (Alpine package)
Published: August 30, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Spoofing attack (CVE-ID: CVE-2020-15665)
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to Firefox does not reset the address bar after the beforeunload dialog is shown if the
user chooses to remain on the page. As a result, an incorrect URL is shown in the address bar.
Remediation
Install update from vendor's website.