PT-2016-7644 · Mozilla+3 · Firefox+3

Markus Stange

·

Published

2016-11-15

·

Updated

2024-12-12

·

CVE-2016-9077

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 50
Description The issue allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, which can lead to timing attacks when the images are loaded from third-party locations.
Recommendations For versions prior to 50, update to a version that contains a fix for this issue to prevent potential timing attacks.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2307
ALT-PU-2017-1578
CVE-2016-9077
MGASA-2017-0323
OPENSUSE-SU-2016_2861-1
OPENSUSE-SU-2016_3011-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2019:2872-1
USN-3124-1

Affected Products

Alt Linux
Firefox
Suse
Ubuntu