A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered without specific user interaction for the file download and open actions. This could be used to trigger known vulnerabilities in the programs that handle those document types. This vulnerability affects Firefox < 56.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/101057 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1039465 | Third Party Advisory VDB Entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=1346515 | Exploit Issue Tracking |
https://www.mozilla.org/security/advisories/mfsa2017-21/ | Vendor Advisory |
http://www.securityfocus.com/bid/101057 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1039465 | Third Party Advisory VDB Entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=1346515 | Exploit Issue Tracking |
https://www.mozilla.org/security/advisories/mfsa2017-21/ | Vendor Advisory |
Configurations
History
21 Nov 2024, 03:32
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/101057 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1039465 - Third Party Advisory, VDB Entry | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1346515 - Exploit, Issue Tracking | |
References | () https://www.mozilla.org/security/advisories/mfsa2017-21/ - Vendor Advisory |
Information
Published : 2018-06-11 21:29
Updated : 2024-11-21 03:32
NVD link : CVE-2017-7821
Mitre link : CVE-2017-7821
CVE.ORG link : CVE-2017-7821
JSON object : View
Products Affected
mozilla
- firefox
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource