Spoofing attack in Mozilla Firefox - CVE-2020-15665

 

Spoofing attack in Mozilla Firefox - CVE-2020-15665

Published: August 25, 2020


Vulnerability identifier: #VU46020
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15665
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to Firefox does not reset the address bar after the beforeunload dialog is  shown if the user chooses to remain on the page. As a result, an incorrect URL is shown in the address bar.


Affected software

Mozilla Firefox
Ubuntu
firefox (Alpine package)
firefox (Ubuntu package)

How to mitigate CVE-2020-15665

Install updates from vendor's website.

Mozilla Firefox - update to 80.0
firefox (Ubuntu package) - addressed in versions 80.0+build2-0ubuntu0.16.04.1, 80.0+build2-0ubuntu0.18.04.1, 80.0+build2-0ubuntu0.20.04.1, 80.0.1+build1-0ubuntu0.16.04.1, 80.0.1+build1-0ubuntu0.18.04.1, 80.0.1+build1-0ubuntu0.20.04.1

External References

Related Security Bulletins