Opened 7 years ago

Closed 7 years ago

Last modified 7 years ago

#8584 closed enhancement (fixed)

firefox 50.0.2 (was 50.0.1)

Reported by: Pierre Labastie Owned by: ken@…
Priority: high Milestone: 8.0
Component: BOOK Version: SVN
Severity: normal Keywords:
Cc:

Description

New point version: security fix:

CVE-2016-9078: data: URL can inherit wrong origin after an HTTP redirect.

Description

Redirection from an HTTP connection to a data: URL assigns the referring
site's origin to the data: URL in some circumstances. This can result in
same-origin violations against a domain if it loads resources from malicious
sites. Cross-origin setting of cookies has been demonstrated without the
ability to read them.
Note: This issue only affects Firefox 49 and 50.

Change History (3)

comment:1 by ken@…, 7 years ago

Owner: changed from blfs-book@… to ken@…
Status: newassigned
Summary: firefox 50.0.1firefox 50.0.2 (was 50.0.1)

50.0.2 fixes CVE-2016-9079, Use after free in SVG Animation. An exploit in the wild targets Windows and Tor users.

comment:2 by ken@…, 7 years ago

Resolution: fixed
Status: assignedclosed

comment:3 by bdubbs@…, 7 years ago

Milestone: 7.118.0

Milestone renamed

Note: See TracTickets for help on using tickets.