Уязвимость DNS Rebinding атаки в Mozilla Firefox и Thunderbird из-за некорректной фильтрации IP адресов при использовании DNS over HTTPS (DoH)
Описание
При использовании DNS over HTTPS (DoH) намеренно отфильтровываются IP-адреса из диапазонов, указанных в RFC1918 и связанных стандартов, так как они не имеют смысла для DoH-резолвера. Однако, когда IPv4-адрес представляется через IPv6, такие адреса некорректно пропускаются, что может привести к потенциальной DNS Rebinding атаке.
Затронутые версии ПО
- Firefox версий до 83
- Firefox ESR версий до 78.5
- Thunderbird версий до 78.5
Тип уязвимости
DNS Rebinding атака
Ссылки
- Issue TrackingPermissions RequiredVendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Issue TrackingPermissions RequiredVendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let through, leading to a potential DNS Rebinding attack. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let through, leading to a potential DNS Rebinding attack. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
When DNS over HTTPS is in use, it intentionally filters RFC1918 and re ...
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let through, leading to a potential DNS Rebinding attack. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
EPSS
6.5 Medium
CVSS3
4.3 Medium
CVSS2