CVE-2017-5454
HIGHRedhat Enterprise Linux < 53.0 - Information Disclosure
Title source: ruleDescription
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. This allows for read only access to the local file system. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
References (8)
Core 8
Core References
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1106
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2017-12/
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2017-10/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/97940
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2017-13/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1038320
Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1349276
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1201
Scores
CVSS v3
7.5
EPSS
0.0053
EPSS Percentile
67.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (15)
mozilla/firefox
< 53.0
mozilla/thunderbird
< 52.1.0
redhat/enterprise_linux
6.0
redhat/enterprise_linux
7.0
redhat/enterprise_linux_desktop
6.0
redhat/enterprise_linux_desktop
7.0
redhat/enterprise_linux_server
6.0
redhat/enterprise_linux_server
7.0
redhat/enterprise_linux_server_aus
7.3
redhat/enterprise_linux_server_aus
7.4
... and 5 more
Published
Jun 11, 2018
Tracked Since
Feb 18, 2026