#VU48470 Information disclosure in Mozilla Firefox and Firefox ESR - CVE-2020-26966
Published: November 17, 2020
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the way Firefox performs searches of single-word queries. Searching for a single word from the address bar cause an mDNS request to be sent on the local network searching for a hostname consisting of that string. A remote attacker with the local network can intercept the DNS query and obtain information, searched via browser address bar.
Note, the vulnerability affects Windows users only.