CVE-2016-9077

critical
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
9.5

Description

Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations. This vulnerability affects Firefox < 50.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2016-9077 NameCVE-2016-9077 DescriptionCanvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations. This vulnerability affects Firefox < 50. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red…

CVE-2016-9077

NameCVE-2016-9077
DescriptionCanvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations. This vulnerability affects Firefox < 50.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
firefox (PTS)sid151.0.3-1fixed
firefox-esr (PTS)bullseye115.14.0esr-1~deb11u1fixed
bullseye (security)140.11.0esr-1~deb11u1fixed
bookworm140.10.2esr-1~deb12u1fixed
bookworm (security)140.11.0esr-1~deb12u1fixed
trixie140.10.2esr-1~deb13u1fixed
trixie (security)140.11.0esr-1~deb13u1fixed
forky, sid140.11.0esr-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
firefoxsource(unstable)50.0-1
firefox-esrsource(unstable)(not affected)

Notes

- firefox-esr <not-affected> (Does not affect Firefox 45 ESR release)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
- firefox-esr <not-affected> (Does not affect Firefox 45 ESR release)

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
Affected
arch Arch Fixed 1 release
VersionStatusFixed in
Fixed 50.0-1
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 0
sid Fixed 50.0-1
forky Fixed 0
bullseye Fixed 0
bookworm Fixed 0

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.