On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
References
Link | Resource |
---|---|
http://www.securitytracker.com/id/1039124 | Third Party Advisory VDB Entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=1374281 | Exploit Issue Tracking Vendor Advisory |
https://www.mozilla.org/security/advisories/mfsa2017-18/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mozilla
Published: 2018-06-11T21:00:00
Updated: 2018-06-12T09:57:01
Reserved: 2017-04-12T00:00:00
Link: CVE-2017-7794
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-06-11T21:29:09.547
Modified: 2019-10-03T00:03:26.223
Link: CVE-2017-7794
JSON object: View
Redhat Information
No data.
CWE