Your submission was sent successfully! Close

CVE-2017-5453

Published: 20 April 2017

A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL parameters for a feed's "TITLE" element. This vulnerability allows for spoofing but no scripted content can be run. This vulnerability affects Firefox < 53.

Priority

Low

CVSS 3 base score: 4.3

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
precise Does not exist
(precise was ignored)
trusty Does not exist
(trusty was released [53.0+build6-0ubuntu0.14.04.1])
upstream
Released (53.0)
xenial
Released (53.0+build6-0ubuntu0.16.04.1)
yakkety
Released (53.0+build6-0ubuntu0.16.10.1)
zesty
Released (53.0+build6-0ubuntu0.17.04.1)
thunderbird
Launchpad, Ubuntu, Debian
precise Does not exist
(precise was needs-triage)
trusty Does not exist
(trusty was not-affected)
upstream Not vulnerable

xenial Not vulnerable

yakkety Not vulnerable

zesty Not vulnerable