mozilla: denial of service
| Package(s): | firefox, nss | CVE #(s): | CVE-2016-2827 | ||||||||||||||||||||
| Created: | September 26, 2016 | Updated: | September 28, 2016 | ||||||||||||||||||||
| Description: | From the CVE entry:
The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a Content Security Policy (CSP) referrer directive with zero values. | ||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||
