SB2020111732 - Information disclosure in firefox-esr (Alpine package)
Published: November 17, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2020-26966)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the way Firefox performs searches of single-word queries. Searching for a single word from the address bar cause an mDNS request to be sent on the local network searching for a hostname consisting of that string. A remote attacker with the local network can intercept the DNS query and obtain information, searched via browser address bar.
Note, the vulnerability affects Windows users only.
Remediation
Install update from vendor's website.