Your submission was sent successfully! Close

CVE-2017-7816

Published: 2 October 2017

WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security checks that disallow this behavior. This vulnerability affects Firefox < 56.

Priority

Medium

CVSS 3 base score: 5.3

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
artful
Released (56.0+build6-0ubuntu1)
bionic
Released (56.0+build6-0ubuntu1)
precise Does not exist

trusty Does not exist
(trusty was released [56.0+build6-0ubuntu0.14.04.1])
upstream
Released (56.0)
xenial
Released (56.0+build6-0ubuntu0.16.04.1)
zesty
Released (56.0+build6-0ubuntu0.17.04.1)