Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7814

Опубликовано: 11 июн. 2018
Источник: debian
EPSS Низкий

Описание

File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed56.0-1package
firefox-esrfixed52.4.0esr-2package
thunderbirdfixed1:52.4.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2017-21/#CVE-2017-7814

  • https://www.mozilla.org/en-US/security/advisories/mfsa2017-22/#CVE-2017-7814

  • https://www.mozilla.org/en-US/security/advisories/mfsa2017-23/#CVE-2017-7814

EPSS

Процентиль: 54%
0.00319
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 7 лет назад

File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.8
redhat
почти 8 лет назад

File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.8
nvd
около 7 лет назад

File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.8
github
около 3 лет назад

File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.5
fstec
около 8 лет назад

Уязвимость реализации функции защиты от вредоносных сайтов и фишинга Phishing and Malware Protection браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю проводить фишинг-атаки

EPSS

Процентиль: 54%
0.00319
Низкий