PT-2017-17945 · Mozilla+3 · Firefox+3

Konark

·

Publicado

2017-12-05

·

Atualizado

2024-12-12

·

CVE-2017-7843

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox ESR versions prior to 52.5.2 Firefox versions prior to 57.0.1
Description The issue allows a web worker to write persistent data to IndexedDB when Private Browsing mode is used, enabling user fingerprinting. IndexedDB should be unavailable in Private Browsing mode, but the stored data persists across multiple private browsing sessions because it is not cleared upon exit.
Recommendations For Firefox ESR versions prior to 52.5.2, update to version 52.5.2 or later. For Firefox versions prior to 57.0.1, update to version 57.0.1 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2739
ALT-PU-2017-2782
ALT-PU-2018-1854
CESA-2017_3382
CVE-2017-7843
DLA-1202-1
DSA-4062-1
MGASA-2017-0448
MGASA-2018-0018
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2017:3382
RHSA-2017_3382

Produtos afetados

Alt Linux
Centos
Firefox
Red Hat