Your submission was sent successfully! Close

CVE-2017-5384

Published: 25 January 2017

Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more information than would be sent to the proxy itself in the case of HTTPS. Normally the Proxy Auto-Config file is specified by the user or machine owner and presumed to be non-malicious, but if a user has enabled Web Proxy Auto Detect (WPAD) this file can be served remotely. This vulnerability affects Firefox < 51.

Priority

Medium

CVSS 3 base score: 5.9

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
precise
Released (51.0.1+build2-0ubuntu0.12.04.1)
trusty Does not exist
(trusty was released [51.0.1+build2-0ubuntu0.14.04.1])
upstream
Released (51)
xenial
Released (51.0.1+build2-0ubuntu0.16.04.1)
yakkety
Released (51.0.1+build2-0ubuntu0.16.10.1)
zesty
Released (52.0.1+build2-0ubuntu1)
thunderbird
Launchpad, Ubuntu, Debian
precise Not vulnerable

trusty Does not exist
(trusty was not-affected)
upstream Not vulnerable

xenial Not vulnerable

yakkety Not vulnerable

zesty Not vulnerable