#VU6345 Information disclosure in Mozilla Firefox - CVE-2017-5468
Published: April 19, 2017
Vulnerability identifier: #VU6345
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-5468
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Mozilla Firefox
Mozilla Firefox
Software vendor:
Mozilla
Mozilla
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an error connected with incorrect ownership model of privateBrowsing. An attacker can expose certain sensitive data through developer tools. This can result in a non-exploitable crash when manually triggered during debugging.
Remediation
Update to Firefox 53.