Permissions, Privileges, and Access Controls in Mozilla Firefox and Firefox ESR - CVE-2020-15653
Published: July 29, 2020
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to application does not properly impose security restrictions, when allowing popups. A remote attacker can create a specially crafted web page with noopener links that may allow an attacker to bypass iframe sandbox for websites relying on sandbox configurations, if allow-popups flag is set.
Affected software
Firefox ESR
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Slackware Linux
Opensuse
Ubuntu
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
firefox (Alpine package)
firefox-esr (Alpine package)
firefox (Red Hat package)
firefox (Ubuntu package)
Mozilla Thunderbird
How to mitigate CVE-2020-15653
Firefox ESR - update to 78.1.0
Mozilla Thunderbird - update to 78.0.1
firefox (Alpine package) - update to 79.0-r0
firefox-esr (Alpine package) - update to 78.1.0-r0
firefox (Red Hat package) - addressed in versions 78.2.0-2.el8_2, 78.2.0-3.el8_0, 78.2.0-3.el8_1, 78.3.0-1.el7_9
firefox (Ubuntu package) - addressed in versions 79.0+build1-0ubuntu0.16.04.2, 79.0+build1-0ubuntu0.18.04.1, 79.0+build1-0ubuntu0.20.04.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Mozilla Thunderbird
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaFirefox
- Permissions, Privileges, and Access Controls in firefox-esr (Alpine package)
- Permissions, Privileges, and Access Controls in firefox (Alpine package)
- Red Hat Enterprise Linux 8 update for firefox
- Red Hat Enterprise Linux 8 update for firefox
- Red Hat Enterprise Linux 8 update for firefox
- Red Hat Enterprise Linux 7 update for firefox
- Ubuntu update for firefox