Security restrictions bypass in Mozilla Firefox - CVE-2017-7843

 

Security restrictions bypass in Mozilla Firefox - CVE-2017-7843

Published: December 5, 2017 / Updated: December 5, 2017


Vulnerability identifier: #VU9527
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7843
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists in web worker while in Private Browsing mode due to improper input validation. A remote attacker can trick the victim into visiting a specially crafted website, bypass private-browsing protections and uniquely fingerprint visitors.to write persistent data to IndexedDB, which was not cleared when exiting and would persist across multiple sessions.

Affected software

Mozilla Firefox
Debian Linux
Gentoo Linux
Red Hat Enterprise Linux for x86_64
firefox-esr (Alpine package)

How to mitigate CVE-2017-7843

Update to version 57.0.1.

firefox-esr (Alpine package) - update to 52.5.2-r0

External References

Related Security Bulletins