CVE-2017-5425

HIGH

Gecko Media Plugin - Info Disclosure

Title source: llm
STIX 2.1

Description

The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of "/private/var" that could expose personal or temporary data. This has been updated to not allow access to "/private/var" and its subdirectories. Note: this issue only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2017-09/
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2017-05/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037966
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1322716
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96692

Scores

CVSS v3 7.5
EPSS 0.0047
EPSS Percentile 64.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
mozilla/firefox < 52.0
mozilla/thunderbird < 52.0
Published Jun 11, 2018
Tracked Since Feb 18, 2026