PT-2017-4016 · Mozilla+2 · Firefox+2
Frederik Braun
·
Publicado
2017-06-13
·
Atualizado
2024-12-12
·
CVE-2017-7799
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 55
Description
The issue is related to the implementation of the WebRTC mechanism in Mozilla Firefox, which fails to protect the structure of web pages. This could potentially allow a remote attacker to conduct cross-site scripting (XSS) attacks. The vulnerability is difficult to exploit because the data is supplied by WebRTC usage and is not under third-party control.
Recommendations
For versions prior to 55, update to version 55 or later to resolve the issue. As a temporary workaround, consider restricting access to the "about:webrtc" page until a patch is available. Avoid using the
innerHTML property in the affected page to minimize the risk of exploitation.Exploit
Correção
Command Injection
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Firefox
Ubuntu