CVE-2016-1955: Infoleak
Published Mar 13, 2016
·Updated
Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.
Affected Software
5 affected components
Novell Suse Package Hub For Suse Linux Enterprise=12
openSUSE Leap=42.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Mozilla Firefox<=44.0.2
Event History
Mar 13, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1955?
CVE-2016-1955 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2016-1955?
To fix CVE-2016-1955, upgrade Mozilla Firefox to version 45.0 or later.
3
Which versions of Firefox are affected by CVE-2016-1955?
CVE-2016-1955 affects all versions of Mozilla Firefox prior to 45.0.
4
What does CVE-2016-1955 exploit in Firefox?
CVE-2016-1955 exploits a vulnerability that allows attackers to bypass the Same Origin Policy.
5
Can CVE-2016-1955 lead to data leakage?
Yes, CVE-2016-1955 can allow remote attackers to obtain sensitive information through CSP violation reports.