PT-2017-17942 · Mozilla+1 · Firefox+1

Xiaoyin Liu

·

Published

2017-08-08

·

Updated

2024-12-12

·

CVE-2017-7790

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 55
Description The issue affects Windows systems, where non-null-terminated strings copied into the crash reporter for specific registry keys can lead to the exposure of private data from the local system. This is due to the copying of stack memory data until a null is found. The attack is limited to Windows operating systems, with other operating systems not being affected.
Recommendations For versions prior to 55, update to version 55 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2017-2060
CVE-2017-7790
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1

Affected Products

Alt Linux
Firefox