CVE-2017-7843
Summary
| CVE | CVE-2017-7843 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-11 21:29:00 UTC |
| Updated | 2018-08-06 16:35:00 UTC |
| Description | When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox ESR < 52.5.2 and Firefox < 57.0.1. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security vulnerabilities fixed in Firefox ESR 52.5.2 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Mozilla Firefox Flaws Lets Remote Users Obtain Potentially Sensitive Information on the Target System - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Mozilla Firefox ESR CVE-2017-7843 Security Bypass Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Mozilla Firefox MFSA2017-27 Multiple Security Vulnerabilities |
BID |
www.securityfocus.com |
Issue Tracking, Third Party Advisory, VDB Entry |
| [SECURITY] [DLA 1202-1] firefox-esr security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| Debian -- Security Information -- DSA-4062-1 firefox-esr |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Access Denied |
CONFIRM |
bugzilla.mozilla.org |
Exploit, Issue Tracking, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox 57.0.1 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500911 Alpine Linux Security Update for firefox-esr
- 504776 Alpine Linux Security Update for firefox-esr
- 710287 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 201802-03)