Blob and data URLs bypass phishing and malware protection warnings in Mozilla Firefox - CVE-2017-7814

 

Blob and data URLs bypass phishing and malware protection warnings in Mozilla Firefox - CVE-2017-7814

Published: September 28, 2017 / Updated: September 29, 2017


Vulnerability identifier: #VU8623
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7814
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass phishing and malware protection warnings.

File downloads encoded with blob: and data: URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious.

Affected software

Mozilla Firefox
Firefox ESR
Gentoo Linux
Arch Linux
Debian Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE Linux
Ubuntu
Mozilla Thunderbird

How to mitigate CVE-2017-7814

Update to version 56.0.


External References

Related Security Bulletins