CVE-2016-2825: Medium severity ubuntu vulnerability
Published Jun 13, 2016
·Updated
Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
Affected Software
8 affected components
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
openSUSE Leap=42.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Mozilla Firefox<=46.0.1
Event History
Jun 13, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2825?
CVE-2016-2825 is considered a moderate severity vulnerability.
2
How do I fix CVE-2016-2825?
To fix CVE-2016-2825, update Mozilla Firefox to version 47.0 or later.
3
Which software is affected by CVE-2016-2825?
CVE-2016-2825 affects versions of Mozilla Firefox prior to 47.0, as well as specific versions of Ubuntu and openSUSE.
4
What type of attack is associated with CVE-2016-2825?
CVE-2016-2825 allows remote attackers to bypass the Same Origin Policy.
5
What does CVE-2016-2825 allow attackers to do?
CVE-2016-2825 allows attackers to modify the location.host property via an invalid data: URL.