PT-2017-17942 · Mozilla+1 · Firefox+1
Xiaoyin Liu
·
Published
2017-08-08
·
Updated
2024-12-12
·
CVE-2017-7790
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 55
Description
The issue affects Windows systems, where non-null-terminated strings copied into the crash reporter for specific registry keys can lead to the exposure of private data from the local system. This is due to the copying of stack memory data until a null is found. The attack is limited to Windows operating systems, with other operating systems not being affected.
Recommendations
For versions prior to 55, update to version 55 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Firefox