CVE-2017-7794

On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
References
Link Resource
http://www.securitytracker.com/id/1039124 Third Party Advisory VDB Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=1374281 Exploit Issue Tracking Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2017-18/ Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-06-11 21:29

Updated : 2024-02-28 16:25


NVD link : CVE-2017-7794

Mitre link : CVE-2017-7794

CVE.ORG link : CVE-2017-7794


JSON object : View

Products Affected

mozilla

  • firefox

linux

  • linux_kernel
CWE
CWE-276

Incorrect Default Permissions