CVE-2017-7843

Publication date 11 June 2018

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

7.5 · High

Score breakdown

When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox ESR < 52.5.2 and Firefox < 57.0.1.

Status

Package Ubuntu Release Status
firefox 18.04 LTS bionic
Fixed 57.0.1+build2-0ubuntu1
17.10 artful
Fixed 57.0.1+build2-0ubuntu0.17.10.1
17.04 zesty
Fixed 57.0.1+build2-0ubuntu0.17.04.1
16.04 LTS xenial
Fixed 57.0.1+build2-0ubuntu0.16.04.1
14.04 LTS trusty
Fixed 57.0.1+build2-0ubuntu0.14.04.1

Severity score breakdown

Parameter Value
Base score 7.5 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N