Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-5409

Опубликовано: 11 июн. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.6
CVSS3: 5.5

Описание

The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 45.8 and Firefox < 52.

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
precise

not-affected

trusty

not-affected

trusty/esm

DNE

trusty was not-affected
upstream

released

52.0
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

not-affected

yakkety

not-affected

Показывать по

EPSS

Процентиль: 30%
0.00109
Низкий

3.6 Low

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
больше 7 лет назад

The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 45.8 and Firefox < 52.

CVSS3: 5.5
debian
больше 7 лет назад

The Mozilla Windows updater can be called by a non-privileged user to ...

CVSS3: 5.5
github
больше 3 лет назад

The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 45.8 and Firefox < 52.

suse-cvrf
почти 9 лет назад

Security update for MozillaFirefox

suse-cvrf
почти 9 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 30%
0.00109
Низкий

3.6 Low

CVSS2

5.5 Medium

CVSS3