Spoofing attack with modal dialogs on non-e10s installations in Mozilla Firefox - CVE-2017-7815

 

Spoofing attack with modal dialogs on non-e10s installations in Mozilla Firefox - CVE-2017-7815

Published: September 28, 2017 / Updated: September 29, 2017


Vulnerability identifier: #VU8626
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7815
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

On pages containing an iframe, the data: protocol can be used to create a modal dialog through Javascript that will have an arbitrary domains as the dialog's location, spoofing of the origin of the modal dialog from the user view.

Note: This attack only affects installations with e10 multiprocess turned off. Installations with e10s turned on do not support the modal dialog functionality.

Affected software

Mozilla Firefox
Ubuntu

How to mitigate CVE-2017-7815

Update to version 56.0.


External References

Related Security Bulletins