Related Vulnerabilities: CVE-2020-15680  

An information disclosure issue has been found in Firefox before 82.0 where if a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to successfully probe whether an external protocol handler was registered.

Severity Medium

Remote Yes

Type Information disclosure

Description

An information disclosure issue has been found in Firefox before 82.0 where if a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to successfully probe whether an external protocol handler was registered.

AVG-1256 firefox 81.0.2-1 82.0-1 Critical Fixed

02 Nov 2020 ASA-202011-1 AVG-1256 firefox Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2020-45/#CVE-2020-15680
https://bugzilla.mozilla.org/show_bug.cgi?id=1658881