← Back

CVE-2017-7794

nvd nist
Published: Jun 11, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.

Affected (1)

Products: Mozilla: Firefox
1 product
Firefox
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 55.0
Running on/withPlatform Versions
Linux
Linux Kernel
All versions

References (6)

Source: security@mozilla.org
Third Party AdvisoryVDB Entry
Source: security@mozilla.org
ExploitIssue TrackingVendor Advisory
Source: security@mozilla.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.