CVE-2017-5425
Last modified
CVE-2017-5425 is a vulnerability of currently unknown severity. The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of "/private/var" that could expose personal or temporary data. EPSS estimates a 1.99% chance of exploitation in the next 30 days.
Description
The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of "/private/var" that could expose personal or temporary data. This has been updated to not allow access to "/private/var" and its subdirectories. Note: this issue only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 52.0 |
| Mozilla | Thunderbird | < 52.0 |
References
- http://www.securityfocus.com/bid/96692Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037966Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1322716Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-05/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-09/Vendor Advisory
- http://www.securityfocus.com/bid/96692Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037966Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1322716Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-05/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-09/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5425?
How severe is CVE-2017-5425?
How do I fix CVE-2017-5425?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-5417When dragging content from the primary browser pane to the a…
- CVE-2017-5418An out of bounds read error occurs when parsing some HTTP di…
- CVE-2017-5419If a malicious site repeatedly triggers a modal authenticati…
- CVE-2017-5420A "javascript:" url loaded by a malicious page can obfuscate…
- CVE-2017-5421A malicious site could spoof the contents of the print previ…
- CVE-2017-5422If a malicious site uses the "view-source:" protocol in a se…
- CVE-2017-5426On Linux, if the secure computing mode BPF (seccomp-bpf) fil…
- CVE-2017-5427A non-existent chrome.manifest file will attempt to be loade…
- CVE-2017-5428An integer overflow in "createImageBitmap()" was reported th…
- CVE-2017-5429Memory safety bugs were reported in Firefox 52, Firefox ESR …
- CVE-2017-5430Memory safety bugs were reported in Firefox 52, Firefox ESR …
- CVE-2017-5432A use-after-free vulnerability occurs during certain text in…
Are you affected by CVE-2017-5425?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
