Information disclosure in Pale Moon - CVE-2017-0381
Published: June 25, 2018 / Updated: July 2, 2018
Vulnerability identifier: #VU13539
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-0381
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to obtain potentially sensitive information.
The vulnerability exists due to a flaw in silk/NLSF_stabilize.c in libopus in Mediaserver. A local attacker can run a specially crafted application to access data outside of its permission levels.
Affected software
Pale Moon
Gentoo Linux
Fedora
SUSE Linux
Opensuse
opus
Gentoo Linux
Fedora
SUSE Linux
Opensuse
opus
How to mitigate CVE-2017-0381
Update to version 27.9.3.
Pale Moon - update to 27.9.3
opus - addressed in versions 1.0.3-2.el5, 1.1.3-2.el6, 1.1.3-2.fc24, 1.1.3-2.fc25
opus - addressed in versions 1.0.3-2.el5, 1.1.3-2.el6, 1.1.3-2.fc24, 1.1.3-2.fc25