PT-2016-1816 · Mozilla+3 · Firefox+3
Sdna.Muneaki.Nishimura
·
Publicado
2016-04-26
·
Atualizado
2024-12-12
·
CVE-2016-2816
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 46.0
Description
The issue allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism. This is achieved via the
multipart/x-mixed-replace content type. The vulnerability is related to insufficient access control in the browser.Recommendations
For versions prior to 46.0, update to version 46.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
multipart/x-mixed-replace content type until a patch is available.Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Firefox
Suse
Ubuntu