CVE-2017-5454Sensitive Information Exposure in Mozilla Firefox

Severity
7.5HIGHNVD
OSV9.8
EPSS
0.5%
top 32.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. This allows for read only access to the local file system. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages10 packages

CVEListV5mozilla/firefoxunspecified53
NVDmozilla/firefox< 53.0+1
CVEListV5mozilla/firefox_esrunspecified52.1
Ubuntumozilla/firefox< 53.0.2+build1-0ubuntu0.14.04.2+3
CVEListV5mozilla/thunderbirdunspecified52.1

Also affects: Enterprise Linux 6.0, 7.0, 7.3, 7.4, 7.5

Patches

🔴Vulnerability Details

6
GHSA
GHSA-4v77-6pxw-9whf: A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file p2022-05-14
CVEList
CVE-2017-5454: A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file p2018-06-11
OSV
thunderbird vulnerabilities2017-05-16
OSV
firefox regression2017-05-11
OSV
firefox vulnerabilities2017-04-21

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2017-05-16
Ubuntu
Firefox regression2017-05-11
Ubuntu
Firefox vulnerabilities2017-04-21
Red Hat
Mozilla: Sandbox escape allowing file system read access through file picker (MFSA 2017-12)2017-04-19
Debian
CVE-2017-5454: firefox - A mechanism to bypass file system access protections in the sandbox to use the f...2017

💬Community

1
Bugzilla
CVE-2017-5454 Mozilla: Sandbox escape allowing file system read access through file picker (MFSA 2017-12)2017-04-19
CVE-2017-5454 — Sensitive Information Exposure | cvebase