Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade librewolfUpgrade firefox-esrUpgrade firefoxUpgrade thunderbird | Aug 22, 2024 | Dec 9, 2020 |
| Mfsa2020 50 | — | Upgrade to Mozilla Firefox version 83.0Upgrade to the latest version of Mozilla Firefox | Nov 18, 2020 | Nov 17, 2020 |
| Mfsa2020 51 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 78.5 | Nov 18, 2020 | Nov 17, 2020 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 78.5Upgrade to the latest version of Mozilla Thunderbird | Nov 18, 2020 | Nov 17, 2020 |
| Oracle Solaris | — | Upgrade web/data/firefox-bookmarks to version 78.5.0-11.4.28.0.1.82.2 on Solaris 11.4Upgrade mail/thunderbird to version 78.5.0-11.4.28.0.1.82.2 on Solaris 11.4Upgrade web/browser/firefox to version 78.5.0-11.4.28.0.1.82.2 on Solaris 11.4 | Jan 19, 2021 | Dec 9, 2020 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translations-commonUpgrade mozillafirefox-buildsymbolsUpgrade MozillaThunderbird-translations-commonUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefox-develUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-other | Nov 25, 2020 | Nov 20, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub