CVE-2017-5456
Summary
| CVE | CVE-2017-5456 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-11 21:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for read and write access to the local file system. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Mozilla Firefox Multiple Bugs Let Remote Users Bypass Security Restrictions, Spoof URLs, Obtain Potentially Sensitive Information, Deny Service, and Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Security vulnerabilities fixed in Firefox 53 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| 1344415 - (CVE-2017-5456) Privilege escalation/Sandbox escape using PFileSystemRequestConstructor |
CONFIRM |
bugzilla.mozilla.org |
Exploit, Issue Tracking, Patch, Vendor Advisory |
| Mozilla Firefox Multiple Security Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox ESR 52.1 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378270 Virtuozzo Linux Security Update for firefox (VZLSA-2017:1106)
- 690289 Free Berkeley Software Distribution (FreeBSD) Security Update for mozilla (5e0a038a-ca30-416d-a2f5-38cbf5e7df33)