CVE-2016-1954: High severity firefox vulnerability
The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote attackers to cause a denial of service (data overwrite) or possibly gain privileges by specifying a URL of a local file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1954?
CVE-2016-1954 is classified as a medium severity vulnerability, allowing denial of service attacks via non-HTTP report-uris.
How do I fix CVE-2016-1954?
To mitigate CVE-2016-1954, users should update to Mozilla Firefox 45.0 or later, or update to the Firefox ESR version 38.7 or later.
Which versions of Firefox are affected by CVE-2016-1954?
CVE-2016-1954 affects Mozilla Firefox versions prior to 45.0 and Firefox ESR versions prior to 38.7.
What kind of attack does CVE-2016-1954 facilitate?
CVE-2016-1954 can enable attackers to send reports to non-HTTP endpoints, potentially causing denial of service.
Are there any specific products affected by CVE-2016-1954?
Yes, CVE-2016-1954 impacts Mozilla Firefox and Mozilla Thunderbird versions up to and including 38.6.1.