CVE-2017-5381Path Traversal in Mozilla Firefox

CWE-22Path Traversal8 documents5 sources
Severity
7.5HIGHNVD
OSV9.8
EPSS
1.3%
top 20.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 13

Description

The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allowing certificate content to be saved in unsafe locations with an arbitrary filename. This vulnerability affects Firefox < 51.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

debiandebian/firefox< firefox 51.0-1 (sid)
CVEListV5mozilla/firefoxunspecified51
NVDmozilla/firefox< 51.0
debiandebian/firefox-esr< firefox 51.0-1 (sid)
Ubuntumozilla/firefox< 51.0.1+build2-0ubuntu0.14.04.1+3

🔴Vulnerability Details

4
GHSA
GHSA-jw7x-8w43-2mrj: The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allowi2022-05-13
OSV
firefox regression2017-02-06
OSV
firefox vulnerabilities2017-01-27
OSV
CVE-2017-5381: The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allowi2017-01-25

📋Vendor Advisories

3
Ubuntu
Firefox regression2017-02-06
Ubuntu
Firefox vulnerabilities2017-01-27
Debian
CVE-2017-5381: firefox - The "export" function in the Certificate Viewer can force local filesystem navig...2017