CVE-2017-5414

MEDIUM

Description

The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to information disclosure, such as the operating system or the local account name. This vulnerability affects Firefox < 52 and Thunderbird < 52.

References

http://www.securityfocus.com/bid/96692

http://www.securitytracker.com/id/1037966

https://bugzilla.mozilla.org/show_bug.cgi?id=1319370

https://www.mozilla.org/security/advisories/mfsa2017-05/

https://www.mozilla.org/security/advisories/mfsa2017-09/

Details

Source: MITRE

Published: 2018-06-11

Updated: 2018-08-02

Type: CWE-200

Risk Information

CVSS v2.0

Base Score: 4.9

Vector: (AV:L/AC:L/Au:N/C:C/I:N/A:N)

Impact Score: 6.9

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3.0

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM