Spoofing attack in Mozilla Firefox - CVE-2020-12408
Published: June 2, 2020 / Updated: July 15, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data when browsing a document hosted on an IP address. A remote attacker can trick the victim to visit a specially crafted website and flip flip domain and path information in the address bar.
Affected software
Arch Linux
Gentoo Linux
firefox (Alpine package)
How to mitigate CVE-2020-12408
firefox (Alpine package) - update to 77.0-r0