Cross-site scripting in Mozilla Firefox and Firefox ESR - CVE-2017-5466
Published: April 19, 2017
Vulnerability details
The vulnerability allows a remote attacker to perform XSS attacks.
The vulnerability exists due to origin confusion when reloading isolated data:text/html URL. If a page is loaded from an original site through a hyperlink and contains a redirect to a data:text/html URL, triggering a reload will run the reloaded data:text/html page with its origin set incorrectly.
Successful exploitation of this vulnerability may allow an attacker to gain access to potentially sensitive information from another domain.
Affected software
Firefox ESR
Arch Linux
Red Hat Enterprise Linux for x86_64
SUSE Linux
Ubuntu
Mozilla Thunderbird
How to mitigate CVE-2017-5466
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Mozilla Thunderbird
- Red Hat update for Mozilla Thunderbird
- SUSE Linux update for MozillaFirefox
- Arch Linux update for firefox
- Ubuntu update for Firefox
- Ubuntu update for Firefox
- OpenSUSE Linux update for Mozilla Firefox
- SUSE Linux update for MozillaFirefox