CVE-2016-9900: High severity thunderbird vulnerability
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Other sources
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of data: URLs. This could allow for cross-domain data leakage.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2016-9900?
CVE-2016-9900 has been classified as a moderate severity vulnerability.
How do I fix CVE-2016-9900?
To fix CVE-2016-9900, update Firefox to version 50.1 or later, or update Firefox ESR and Thunderbird to versions 45.6 or later.
What versions of Firefox are affected by CVE-2016-9900?
CVE-2016-9900 affects Firefox versions prior to 50.1.
Which versions of Thunderbird are impacted by CVE-2016-9900?
Thunderbird versions below 45.6 are affected by CVE-2016-9900.
What are the potential consequences of CVE-2016-9900?
CVE-2016-9900 could lead to cross-domain data leakage due to improper handling of external resources in SVG images.