CVE-2017-5386
Published: 25 January 2017
WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensions. This vulnerability affects Firefox ESR < 45.7 and Firefox < 51.
Priority
CVSS 3 base score: 7.3
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
Upstream |
Released
(51)
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(51.0.1+build2-0ubuntu0.16.04.1)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
(trusty was released [51.0.1+build2-0ubuntu0.14.04.1])
|
|
thunderbird Launchpad, Ubuntu, Debian |
Upstream |
Not vulnerable
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Not vulnerable
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
(trusty was not-affected)
|