CVE-2017-7794

high

Description

On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.

References

http://www.securitytracker.com/id/1039124

https://bugzilla.mozilla.org/show_bug.cgi?id=1374281

https://www.mozilla.org/security/advisories/mfsa2017-18/

Details

Source: MITRE

Published: 2018-06-11

Updated: 2019-10-03

Type: CWE-276

Risk Information

CVSS v2

Base Score: 4.6

Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH