A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be displayed. This allows an attacker to spoof which page is actually loaded and in use. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 56.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1039465 | vdb entry third party advisory |
https://www.mozilla.org/security/advisories/mfsa2017-21/ | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1356596 | issue tracking exploit |
http://www.securityfocus.com/bid/101057 | vdb entry third party advisory |