Information disclosure in Firefox ESR and Mozilla Firefox - CVE-2020-26966

 

Information disclosure in Firefox ESR and Mozilla Firefox - CVE-2020-26966

Published: November 17, 2020


Vulnerability identifier: #VU48470
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-26966
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the way Firefox performs searches of single-word queries. Searching for a single word from the address bar cause an mDNS request to be sent on the local network searching for a hostname consisting of that string. A remote attacker with the local network can intercept the DNS query and obtain information, searched via browser address bar.

Note, the vulnerability affects Windows users only.


Affected software

Firefox ESR
Mozilla Firefox
Mozilla Thunderbird
firefox (Alpine package)
firefox-esr (Alpine package)
thunderbird (Alpine package)
Firefox for Android

How to mitigate CVE-2020-26966

Install updates from vendor's website.

Firefox ESR - update to 78.5.0
Mozilla Firefox - update to 83.0
Mozilla Thunderbird - update to 78.5.0
firefox-esr (Alpine package) - update to 78.5.0-r0
thunderbird (Alpine package) - update to 78.5.1-r0
Firefox for Android - update to 83.0.0

External References

Related Security Bulletins