VDB
BDU%3A2020-05846
BDU%3A2020-05846
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Уязвимость механизма подмены адресной строки через взаимодействие пользователя с адресной строкой и событием «onblur» браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю проводить спуфинг-атаки
Risk Scores
CVSS 2.0
4.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «РусБИТех-Астра», Red Hat Inc., Canonical Ltd., АО «ИВК», Novell Inc., Mozilla Corp. | Astra Linux Special Edition (запись в едином реестре российских программ №369), Red Hat Enterprise Linux, Ubuntu, Альт Линукс СПТ (запись в едином реестре российских программ №9), OpenSUSE Leap, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Software Development Kit, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Server for Raspberry Pi, Firefox, Thunderbird, Firefox ESR |
Timeline
- Dec 28, 2020 CVE Published
- Jan 12, 2021 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1273537 url
- https://nvd.nist.gov/vuln/detail/CVE-2017-5451 url
- https://www.mozilla.org/security/advisories/mfsa2017-12/ url
- https://www.suse.com/security/cve/CVE-2017-5451/ url
- https://access.redhat.com/security/cve/cve-2017-5451 url
- https://wiki.astralinux.ru/astra-linux-se15-bulletin-20201201SE15 url
- https://cve.basealt.ru/ url
- https://ubuntu.com/security/notices/USN-3260-1?_ga=2.91217818.1630830267.1608209597-1543702552.1605094901 url
- https://ubuntu.com/security/notices/USN-3278-1?_ga=2.91217818.1630830267.1608209597-1543702552.1605094901 url
- https://www.mozilla.org/security/advisories/mfsa2017-10/ advisory
- https://www.mozilla.org/security/advisories/mfsa2017-13/ advisory
- https://wiki.astralinux.ru/pages/viewpage.action?pageId=1212483 advisory