CVE-2016-2820

Published: 27 April 2016

The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

Priority

Medium

CVSS 3 base score: 4.3

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
Upstream
Released (46.0)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (46.0+build5-0ubuntu0.16.04.2)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was released [46.0+build5-0ubuntu0.14.04.2])
thunderbird
Launchpad, Ubuntu, Debian
Upstream Not vulnerable

Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was not-affected)