Your submission was sent successfully! Close

CVE-2017-7812

Published: 2 October 2017

If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that otherwise would not be allowed to open. This can allow malicious web content to open a locally stored file through "file:" URLs. This vulnerability affects Firefox < 56.

Priority

Medium

CVSS 3 base score: 5.3

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
artful
Released (56.0+build6-0ubuntu1)
bionic
Released (56.0+build6-0ubuntu1)
precise Does not exist

trusty Does not exist
(trusty was released [56.0+build6-0ubuntu0.14.04.1])
upstream
Released (56.0)
xenial
Released (56.0+build6-0ubuntu0.16.04.1)
zesty
Released (56.0+build6-0ubuntu0.17.04.1)