CVE-2020-15680: Medium severity firefox vulnerability
If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to successfully probe whether an external protocol handler was registered.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-15680?
CVE-2020-15680 is a vulnerability in Mozilla Firefox that allows an attacker to probe whether an external protocol handler is registered.
How does CVE-2020-15680 work?
CVE-2020-15680 works by referencing a valid external protocol handler in an image tag, allowing the attacker to distinguish between a broken image size of a non-existent protocol handler and a broken image size of a registered protocol handler.
What is the severity of CVE-2020-15680?
The severity of CVE-2020-15680 is medium, with a severity value of 4.
Which software is affected by CVE-2020-15680?
Mozilla Firefox version up to but excluding 82 is affected by CVE-2020-15680.
How can I fix CVE-2020-15680?
To fix CVE-2020-15680, update Mozilla Firefox to version 82 or newer.