PT-2017-16478 · Mozilla+3 · Firefox+3

Jerri Rice

·

Published

2017-01-24

·

Updated

2024-12-12

·

CVE-2017-5391

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 51
Description The issue concerns the loading of privileged "about:" pages in an iframe by special "about:" pages used by web content, such as RSS feeds. This could potentially allow for privilege escalation if a content-injection bug were found in one of those pages.
Recommendations For versions prior to 51, update to version 51 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2017-1138
ALT-PU-2017-1578
CVE-2017-5391
MGASA-2017-0323
OPENSUSE-SU-2017_0358-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3175-1
USN-3175-2

Affected Products

Alt Linux
Firefox
Suse
Ubuntu