Bugzilla – Bug 1012807
VUL-0: CVE-2016-9078: MozillaFirefox: data: URL can inherit wrong origin after an HTTP redirect
Last modified: 2020-04-05 18:05:20 UTC
https://www.mozilla.org/en-US/security/advisories/mfsa2016-91/ Security vulnerabilities fixed in Firefox 50.0.1 Announced: November 28, 2016 Products: Firefox Fixed in: Firefox 50.0.1 CVE-2016-9078: data: URL can inherit wrong origin after an HTTP redirect Reporter: Alexander Inführ Impact: critical Description: Redirection from an HTTP connection to a data: URL assigns the referring site's origin to the data: URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross-origin setting of cookies has been demonstrated without the ability to read them. Note: This issue only affects Firefox 49 and 50. References: https://bugzilla.mozilla.org/show_bug.cgi?id=1317641
This is an autogenerated message for OBS integration: This bug (1012807) was mentioned in https://build.opensuse.org/request/show/442951 13.2+42.1+42.2 / MozillaFirefox
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (1012807) was mentioned in https://build.opensuse.org/request/show/442963 Factory / MozillaFirefox https://build.opensuse.org/request/show/442964 42.2 / MozillaFirefox https://build.opensuse.org/request/show/442965 42.1 / MozillaFirefox https://build.opensuse.org/request/show/442966 13.2 / MozillaFirefox https://build.opensuse.org/request/show/442967 13.1 / MozillaFirefox
This is an autogenerated message for OBS integration: This bug (1012807) was mentioned in https://build.opensuse.org/request/show/443687 13.1 / MozillaFirefox
openSUSE-SU-2016:2994-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1012807,1012964 CVE References: CVE-2016-9078,CVE-2016-9079 Sources used: openSUSE Leap 42.2 (src): MozillaFirefox-50.0.2-42.2 openSUSE Leap 42.1 (src): MozillaFirefox-50.0.2-42.1 openSUSE 13.2 (src): MozillaFirefox-50.0.2-91.1
openSUSE-SU-2016:3011-1: An update that fixes 30 vulnerabilities is now available. Category: security (important) Bug References: 1009026,1010401,1010404,1010410,1010411,1010427,1012807,1012964 CVE References: CVE-2016-5289,CVE-2016-5290,CVE-2016-5291,CVE-2016-5292,CVE-2016-5293,CVE-2016-5294,CVE-2016-5295,CVE-2016-5296,CVE-2016-5297,CVE-2016-5298,CVE-2016-5299,CVE-2016-9061,CVE-2016-9062,CVE-2016-9063,CVE-2016-9064,CVE-2016-9065,CVE-2016-9066,CVE-2016-9067,CVE-2016-9068,CVE-2016-9069,CVE-2016-9070,CVE-2016-9071,CVE-2016-9072,CVE-2016-9073,CVE-2016-9074,CVE-2016-9075,CVE-2016-9076,CVE-2016-9077,CVE-2016-9078,CVE-2016-9079 Sources used: openSUSE 13.1 (src): MozillaFirefox-50.0.2-131.1, MozillaThunderbird-45.5.1-70.92.1, mozilla-nss-3.26.2-94.1
released