HIGH
Mozilla: Linux file truncation via sandbox broker (MFSA 2017-18)
Published Jun 11, 2018
7.8
HIGHCVSS 3.0
EPSS 0.34%
Description
On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<55
- Version
AND
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 6
firefox
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- http://www.securitytracker.com/id/1039124 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2017-7794 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1374281 x_refsource_CONFIRMExploitIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1479211 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2017-7794
- https://www.cve.org/CVERecord?id=CVE-2017-7794
- https://www.mozilla.org/en-US/security/advisories/mfsa2017-18/#CVE-2017-7794
- https://www.mozilla.org/security/advisories/mfsa2017-18/ x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securitytracker.com/id/1039124 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2017-7794 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1374281 | x_refsource_CONFIRMExploitIssue TrackingVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1479211 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-7794 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-7794 | ||
| https://www.mozilla.org/en-US/security/advisories/mfsa2017-18/#CVE-2017-7794 | ||
| https://www.mozilla.org/security/advisories/mfsa2017-18/ | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Jun 11, 2018
Updated Aug 5, 2024
Reserved Apr 12, 2017
Link CVE-2017-7794
CISA Vulnrichment
Updated n/a