Security researcher Tsubasa Iinuma reported a mechanism where the displayed addressbar can be spoofed to users. This issue involves using history navigation in concert with Location protocol property. After navigating from a malicious page to another, if the user navigates back to the initial page, the displayed URL will not reflect the reloaded page. This could be used to trick users into potentially treating the page as a different and trusted site. External Reference: https://www.mozilla.org/security/announce/2016/mfsa2016-28.html Acknowledgements: Name: the Mozilla project Upstream: Tsubasa Iinuma
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Red Hat Enterprise Linux 5 Via RHSA-2016:0373 https://rhn.redhat.com/errata/RHSA-2016-0373.html