CVE-2017-7814Improper Input Validation in Mozilla Firefox

Severity
7.8HIGHNVD
OSV9.8
EPSS
0.3%
top 45.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages11 packages

CVEListV5mozilla/firefoxunspecified56
NVDmozilla/firefox< 52.4.0+1
CVEListV5mozilla/firefox_esrunspecified52.4
Ubuntumozilla/firefox< 56.0+build6-0ubuntu0.14.04.1+3
CVEListV5mozilla/thunderbirdunspecified52.4

Also affects: Debian Linux 7.0, 8.0, 9.0, Enterprise Linux 7.4, 7.5

Patches

🔴Vulnerability Details

6
GHSA
GHSA-95j8-9fpj-7wc6: File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature a2022-05-14
CVEList
CVE-2017-7814: File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature a2018-06-11
OSV
CVE-2017-7814: File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature a2018-06-11
OSV
thunderbird vulnerabilities2017-10-11
OSV
firefox regression2017-10-04

📋Vendor Advisories

5
Ubuntu
Thunderbird vulnerabilities2017-10-11
Ubuntu
Firefox regression2017-10-04
Ubuntu
Firefox vulnerabilities2017-10-02
Red Hat
Mozilla: Blob and data URLs bypass phishing and malware protection warnings (MFSA 2017-22)2017-09-28
Debian
CVE-2017-7814: firefox - File downloads encoded with "blob:" and "data:" URL elements bypassed normal fil...2017

💬Community

1
Bugzilla
CVE-2017-7814 Mozilla: Blob and data URLs bypass phishing and malware protection warnings (MFSA 2017-22)2017-09-28
CVE-2017-7814 — Improper Input Validation in Mozilla | cvebase