---
title: "CVE-2017-7839\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2017-7839?format=md
keywords: index, follow
---

# CVE-2017-7839

Publication date 15 November 2017

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.1 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2017-7839?format=md#impact-score)

Toggle side navigation

## Description

Control characters prepended before "javascript:" URLs pasted in the
addressbar can cause the leading characters to be ignored and the pasted
JavaScript to be executed instead of being blocked. This could be used in
social engineering and self-cross-site-scripting (self-XSS) attacks where
users are convinced to copy and paste text into the addressbar. This
vulnerability affects Firefox < 57.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 18.04 LTS bionic | Fixed 57.0.1+build2-0ubuntu1 |
| 17.10 artful | Fixed 57.0+build4-0ubuntu0.17.10.5 |
| 17.04 zesty | Fixed 57.0+build4-0ubuntu0.17.04.5 |
| 16.04 LTS xenial | Fixed 57.0+build4-0ubuntu0.16.04.5 |
| 14.04 LTS trusty | Fixed 57.0+build4-0ubuntu0.14.04.4 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.1 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Changed |
  | Confidentiality impact | Low |
  | Integrity impact | Low |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.1 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7839)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-7839)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2017-7839)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2017-7839)

### Related Ubuntu Security Notices (USN)

+ [USN-3477-1](https://usn.ubuntu.com/USN-3477-1)
+ Firefox vulnerabilities
+ 16 November 2017

### Other references

* <https://www.mozilla.org/en-US/security/advisories/mfsa2017-24/>
* <https://www.cve.org/CVERecord?id=CVE-2017-7839>
