CVE-2016-9064: Medium severity firefox vulnerability
Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perform a man-in-the-middle attack on the user's connection to the update server and defeat the certificate pinning protection could provide a malicious signed add-on instead of a valid update.
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2016-5296
- CVE-2016-5292
- CVE-2016-5293
- CVE-2016-5294
- CVE-2016-5297
- CVE-2016-9064
- CVE-2016-9065
- CVE-2016-9066
- CVE-2016-9067
- CVE-2016-9068
- CVE-2016-9072
- CVE-2016-9075
- CVE-2016-9077
- CVE-2016-5291
- CVE-2016-5295
- CVE-2016-5298
- CVE-2016-5299
- CVE-2016-9061
- CVE-2016-9062
- CVE-2016-9070
- CVE-2016-9073
- CVE-2016-9074
- CVE-2016-9076
- CVE-2016-9063
- CVE-2016-9071
- CVE-2016-5289
- CVE-2016-5290
Frequently Asked Questions
What is CVE-2016-9064?
CVE-2016-9064 is a vulnerability that allowed an attacker to provide a malicious signed package during add-on updates in Mozilla Firefox.
What software versions are affected by CVE-2016-9064?
Mozilla Firefox versions up to and including 50, and Mozilla Firefox ESR versions up to and including 45.5 are affected by CVE-2016-9064.
How severe is CVE-2016-9064?
CVE-2016-9064 has a severity rating of 7 (high).
How can an attacker exploit CVE-2016-9064?
By performing a man-in-the-middle attack on the user's connection to the update server and defeating the certificate pinning protection, an attacker can provide a malicious signed package during add-on updates.
Where can I find more information about CVE-2016-9064?
You can find more information about CVE-2016-9064 on the Mozilla Bugzilla page (https://bugzilla.mozilla.org/show_bug.cgi?id=1303418) and the Mozilla Security Advisories (https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/ and https://www.mozilla.org/en-US/security/advisories/mfsa2016-90/).