Spoofing attack in Mozilla Firefox - CVE-2020-26979

 

Spoofing attack in Mozilla Firefox - CVE-2020-26979

Published: December 15, 2020


Vulnerability identifier: #VU49021
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-26979
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to the way Firefox processes events, related to URL processing in the address bar. When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then redirect the user before navigation occurred to the desired, entered address. To construct a convincing spoof the attacker would have had to guess what the user was typing, perhaps by suggesting it.


Affected software

Mozilla Firefox
Arch Linux
Ubuntu
openEuler
firefox (Alpine package)
firefox
firefox-debuginfo
firefox-debugsource
mozilla-crashreporter-firefox-debuginfo
firefox (Ubuntu package)

How to mitigate CVE-2020-26979

Install updates from vendor's website.

Mozilla Firefox - update to 84.0
firefox (Alpine package) - update to 84.0.1-r0
firefox - update to 79.0-32
firefox-debuginfo - update to 79.0-32
firefox-debugsource - update to 79.0-32
mozilla-crashreporter-firefox-debuginfo - update to 79.0-32
firefox (Ubuntu package) - addressed in versions 84.0+build3-0ubuntu0.16.04.1, 84.0+build3-0ubuntu0.18.04.1, 84.0+build3-0ubuntu0.20.04.1, 84.0+build3-0ubuntu0.20.10.1

External References

Related Security Bulletins