PT-2016-2520 · Mozilla+3 · Firefox+3

Rafael Gieschke

·

Published

2016-08-02

·

Updated

2024-12-12

·

CVE-2016-5266

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 48.0
Description The issue is related to improper restriction of drag-and-drop operations for file: URL objects, which can be exploited by a remote attacker using a specially crafted website to access local files. This can allow user-assisted remote attackers to obtain access to local files.
Recommendations For versions prior to 48.0, update to version 48.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of drag-and-drop functionality in Firefox until a patch is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1836
ALT-PU-2017-1578
BDU:2016-01911
CVE-2016-5266
OPENSUSE-SU-2016_1964-1
OPENSUSE-SU-2016_2026-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-3044-1

Affected Products

Alt Linux
Firefox
Suse
Ubuntu