On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
References
Link | Resource |
---|---|
https://www.mozilla.org/security/advisories/mfsa2017-18/ | Vendor Advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1374281 | Exploit Issue Tracking Vendor Advisory |
http://www.securitytracker.com/id/1039124 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2018-06-11 14:29
Updated : 2019-10-02 17:03
NVD link : CVE-2017-7794
Mitre link : CVE-2017-7794
JSON object : View
CWE
CWE-276
Incorrect Default Permissions
Products Affected
mozilla
- firefox
linux
- linux_kernel