Information disclosure in Firefox ESR and Mozilla Firefox - CVE-2020-26966
Published: November 17, 2020
Firefox ESR
Mozilla Firefox
Mozilla Thunderbird
firefox (Alpine package)
firefox-esr (Alpine package)
thunderbird (Alpine package)
Firefox for Android
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the way Firefox performs searches of single-word queries. Searching for a single word from the address bar cause an mDNS request to be sent on the local network searching for a hostname consisting of that string. A remote attacker with the local network can intercept the DNS query and obtain information, searched via browser address bar.
Note, the vulnerability affects Windows users only.