First published: Tue Nov 17 2020(Updated: )
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <78.5 | 78.5 |
<83 | 83 | |
<78.5 | 78.5 | |
<78.5 | 78.5 | |
Mozilla Firefox | <83.0 | |
Mozilla Firefox ESR | <78.5 | |
Mozilla Thunderbird | <78.5 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-26966 is a vulnerability that affects Windows operating systems and allows for an information leak when searching for a single word from the address bar in Mozilla Firefox and Thunderbird.
Only Windows operating systems are affected by CVE-2020-26966.
Mozilla Firefox ESR versions up to 78.5, Mozilla Thunderbird up to 78.5, and Mozilla Firefox up to version 83.0 are affected by CVE-2020-26966.
CVE-2020-26966 has a severity rating of 6.5 (Medium).
To mitigate the vulnerability, update Mozilla Firefox ESR to version 78.5, Mozilla Thunderbird to version 78.5, and Mozilla Firefox to version 83.0 or later.