The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege if combined with another vulnerability that resulted in remote code execution inside the sandboxed process. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.
http://www.securityfocus.com/bid/97940
http://www.securitytracker.com/id/1038320
https://access.redhat.com/errata/RHSA-2017:1106
https://bugzilla.mozilla.org/show_bug.cgi?id=1341191
Source: MITRE
Published: 2018-06-11
Updated: 2019-10-03
Type: NVD-CWE-noinfo
Base Score: 5
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
Impact Score: 2.9
Exploitability Score: 10
Severity: MEDIUM
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Impact Score: 3.6
Exploitability Score: 3.9
Severity: HIGH
OR
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
OR
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
102694 | SUSE SLES11 Security Update : MozillaFirefox, MozillaFirefox-branding-SLED, firefox-gcc5, mozilla-nss (SUSE-SU-2017:2235-1) | Nessus | SuSE Local Security Checks | high |
101457 | Virtuozzo 7 : firefox (VZLSA-2017-1106) | Nessus | Virtuozzo Local Security Checks | high |
101055 | SUSE SLED12 / SLES12 Security Update : MozillaFirefox, MozillaFirefox-branding-SLE (SUSE-SU-2017:1669-1) | Nessus | SuSE Local Security Checks | high |
100688 | EulerOS 2.0 SP2 : firefox (EulerOS-SA-2017-1093) | Nessus | Huawei Local Security Checks | high |
100687 | EulerOS 2.0 SP1 : firefox (EulerOS-SA-2017-1092) | Nessus | Huawei Local Security Checks | high |
100153 | Ubuntu 14.04 LTS / 16.04 LTS / 16.10 / 17.04 : firefox regression (USN-3260-2) | Nessus | Ubuntu Local Security Checks | high |
99632 | Mozilla Firefox < 53 Multiple Vulnerabilities | Nessus | Windows | high |
99631 | Mozilla Firefox ESR 52.x < 52.1 Multiple Vulnerabilities | Nessus | Windows | high |
99629 | Mozilla Firefox < 53 Multiple Vulnerabilities (macOS) | Nessus | MacOS X Local Security Checks | high |
99628 | Mozilla Firefox ESR < 52.1 Multiple Vulnerabilities (macOS) | Nessus | MacOS X Local Security Checks | high |
99626 | Ubuntu 14.04 LTS / 16.04 LTS / 16.10 / 17.04 : firefox vulnerabilities (USN-3260-1) | Nessus | Ubuntu Local Security Checks | high |
99619 | Scientific Linux Security Update : firefox on SL7.x x86_64 (20170420) | Nessus | Scientific Linux Local Security Checks | high |
99572 | RHEL 7 : firefox (RHSA-2017:1106) | Nessus | Red Hat Local Security Checks | high |
99565 | Oracle Linux 7 : firefox (ELSA-2017-1106) | Nessus | Oracle Linux Local Security Checks | high |
99539 | CentOS 7 : firefox (CESA-2017:1106) | Nessus | CentOS Local Security Checks | high |
700065 | Mozilla Firefox < 53 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
99496 | FreeBSD : mozilla -- multiple vulnerabilities (5e0a038a-ca30-416d-a2f5-38cbf5e7df33) | Nessus | FreeBSD Local Security Checks | high |