CVE-2016-2829: Medium severity ubuntu vulnerability
Published Jun 13, 2016
·Updated
Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation permission.
Affected Software
8 affected components
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.10
Canonical Ubuntu Linux=16.04
Mozilla Firefox<=46.0.1
openSUSE Leap=42.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Event History
Jun 13, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2829?
CVE-2016-2829 is rated as a moderate severity vulnerability.
2
How do I fix CVE-2016-2829?
To fix CVE-2016-2829, update your Mozilla Firefox to version 47.0 or later.
3
Who is affected by CVE-2016-2829?
CVE-2016-2829 primarily affects users of Mozilla Firefox version 46.0.1 and earlier on various Linux distributions.
4
What does CVE-2016-2829 exploit in Firefox?
CVE-2016-2829 exploits a weakness that allows attackers to spoof permission notifications through rapid permission request triggers.
5
Is there a workaround for CVE-2016-2829?
A temporary workaround for CVE-2016-2829 is to disable permissions for microphone and geolocation in Firefox settings.