Mozilla Firefox CVE-2015-0812 Request Smuggling Vulnerability

description-logoDescription

Security researcher Armin Razmdjou discovered that a man-in-the-middle (MITM) attacker spoofing a Mozilla sub-domain could bypass user approval messages to install a Firefox lightweight theme. This was possible because add-on installations of the lightweight themes do not require the use of HTTP over SSL. Firefox extensions were not directly affected and still required user approval for installation.

affected-products-logoAffected Applications

Firefox

CVE References

CVE-2015-0812