CVE-2016-2822: Medium severity debian linux vulnerability
Published Jun 13, 2016
·Updated
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
Affected Software
13 affected components
Debian Debian Linux=8.0
Mozilla Firefox=45.1.0
Mozilla Firefox=45.1.1
Mozilla Firefox<=46.0.1
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
openSUSE Leap=42.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Mozilla Firefox ESR=45.1.0
Mozilla Firefox ESR=45.1.1
Event History
Jun 13, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2822?
CVE-2016-2822 is considered a medium severity vulnerability as it involves the potential spoofing of the address bar.
2
How do I fix CVE-2016-2822?
To fix CVE-2016-2822, users should update their Mozilla Firefox or Firefox ESR to version 47.0 or later.
3
What versions are affected by CVE-2016-2822?
CVE-2016-2822 affects Mozilla Firefox versions before 47.0 and Firefox ESR versions 45.x before 45.2.
4
Can CVE-2016-2822 be exploited remotely?
Yes, CVE-2016-2822 can be exploited remotely by attackers using a SELECT element with a persistent menu.
5
Is there any specific operating system that CVE-2016-2822 impacts?
CVE-2016-2822 impacts multiple operating systems that run the vulnerable versions of Mozilla Firefox or Firefox ESR.