CVE-2017-7794
Last modified
CVE-2017-7794 is a vulnerability of currently unknown severity. On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 55.0 |
References
- http://www.securitytracker.com/id/1039124Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1374281Exploit, Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-18/Vendor Advisory
- http://www.securitytracker.com/id/1039124Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1374281Exploit, Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-18/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7794?
How severe is CVE-2017-7794?
How do I fix CVE-2017-7794?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7788When an "iframe" has a "sandbox" attribute and its content i…
- CVE-2017-7789If a server sends two Strict-Transport-Security (STS) header…
- CVE-2017-7790On Windows systems, if non-null-terminated strings are copie…
- CVE-2017-7791On pages containing an iframe, the "data:" protocol can be u…
- CVE-2017-7792A buffer overflow will occur when viewing a certificate in t…
- CVE-2017-7793A use-after-free vulnerability can occur in the Fetch API wh…
- CVE-2017-7796On Windows systems, the logger run by the Windows updater de…
- CVE-2017-7797Response header name interning does not have same-origin pro…
- CVE-2017-7798The Developer Tools feature suffers from a XUL injection vul…
- CVE-2017-7799JavaScript in the "about:webrtc" page is not sanitized prope…
- CVE-2017-7800A use-after-free vulnerability can occur in WebSockets when …
- CVE-2017-7801A use-after-free vulnerability can occur while re-computing …
Are you affected by CVE-2017-7794?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
