PT-2017-16511 · Mozilla+2 · Firefox+2

Jose María Acuña

·

Publicado

2017-04-19

·

Atualizado

2024-12-12

·

CVE-2017-5453

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 53
Description The issue is related to a mechanism that allows injecting static HTML into the RSS reader preview page. This is due to a failure to properly escape characters sent as URL parameters for a feed's TITLE element. The issue allows for spoofing, but it does not permit the execution of scripted content.
Recommendations For versions prior to 53, update to version 53 or later to resolve the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1577
ALT-PU-2018-1854
CVE-2017-5453
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3260-1
USN-3260-2

Produtos afetados

Alt Linux
Firefox
Ubuntu