Related Vulnerabilities: CVE-2016-9077  

Canvas allows the use of the feDisplacementMap filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations.

Severity High

Remote Yes

Type Information disclosure

Description

Canvas allows the use of the feDisplacementMap filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations.

AVG-72 firefox 49.0.2-1 50.0-1 Critical Fixed

16 Nov 2016 ASA-201611-16 AVG-72 firefox Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/#CVE-2016-9077