A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for read and write access to the local file system. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.
References
Link | Resource |
---|---|
https://www.mozilla.org/security/advisories/mfsa2017-12/ | Vendor Advisory |
https://www.mozilla.org/security/advisories/mfsa2017-10/ | Vendor Advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1344415 | Exploit Issue Tracking Patch Vendor Advisory |
https://access.redhat.com/errata/RHSA-2017:1106 | Third Party Advisory |
http://www.securitytracker.com/id/1038320 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/97940 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2018-06-11 14:29
Updated : 2019-10-02 17:03
NVD link : CVE-2017-5456
Mitre link : CVE-2017-5456
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
redhat
- enterprise_linux_desktop
- enterprise_linux
- enterprise_linux_server_aus
- enterprise_linux_workstation
- enterprise_linux_server_eus
- enterprise_linux_server
mozilla
- firefox_esr
- firefox