Information disclosure in Mozilla Firefox - CVE-2020-15680

 

Information disclosure in Mozilla Firefox - CVE-2020-15680

Published: October 20, 2020


Vulnerability identifier: #VU47743
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15680
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the way Firefox handles image tags. A remote attacker can use a specially crafted image tag to reference protocol handlers and depending on the response to determine if the requested external protocol handler is registered on the system.


Affected software

Mozilla Firefox
Arch Linux
Ubuntu
firefox (Alpine package)
firefox (Ubuntu package)

How to mitigate CVE-2020-15680

Install updates from vendor's website.

Mozilla Firefox - update to 82.0
firefox (Ubuntu package) - addressed in versions 82.0+build2-0ubuntu0.16.04.5, 82.0+build2-0ubuntu0.18.04.1, 82.0+build2-0ubuntu0.20.04.1, 82.0+build2-0ubuntu0.20.10.1

External References

Related Security Bulletins