Mozilla Firefox Security Restriction Bypass Vulnerability (CVE-2016-2831)
Mozilla Firefox Security Restriction Bypass Vulnerability (CVE-2016-2831)
Release date:
Updated on:
Affected Systems:
Mozilla Firefox & lt; 47.0
Description:
CVE (CAN) ID: CVE-2016-2831
Mozilla Firefox is an open-source web browser that uses the Gecko engine.
Mozilla Firefox <47.0 and Firefox ESR 45.x <45.2 do not ensure that the fullscreen and pointerlock settings are determined by users. A security vulnerability exists, allowing remote attackers to construct websites, this vulnerability may cause denial-of-service attacks or click support or spoofing attacks.
<* Source: Mozilla
Link: https://www.mozilla.org/en-US/security/advisories/mfsa2016-58/
*>
Suggestion:
Vendor patch:
Mozilla
-------
Mozilla has released a Security Bulletin (mfsa2016-58) and patches for this:
Mfsa2016-58: Entering fullscreen and persistent pointerlock without user permission
Link: https://www.mozilla.org/en-US/security/advisories/mfsa2016-58/
This article permanently updates the link address: