On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
References
Link Resource
http://www.securitytracker.com/id/1039124 Third Party Advisory VDB Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=1374281 Exploit Issue Tracking Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2017-18/ Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mozilla

Published: 2018-06-11T21:00:00

Updated: 2018-06-12T09:57:01

Reserved: 2017-04-12T00:00:00


Link: CVE-2017-7794

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-06-11T21:29:09.547

Modified: 2019-10-03T00:03:26.223


Link: CVE-2017-7794

JSON object: View

cve-icon Redhat Information

No data.

CWE