PT-2017-17945 · Mozilla+3 · Firefox+3

Konark

·

Published

2017-12-05

·

Updated

2024-12-12

·

CVE-2017-7843

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox ESR versions prior to 52.5.2 Firefox versions prior to 57.0.1
Description The issue allows a web worker to write persistent data to IndexedDB when Private Browsing mode is used, enabling user fingerprinting. IndexedDB should be unavailable in Private Browsing mode, but the stored data persists across multiple private browsing sessions because it is not cleared upon exit.
Recommendations For Firefox ESR versions prior to 52.5.2, update to version 52.5.2 or later. For Firefox versions prior to 57.0.1, update to version 57.0.1 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2739
ALT-PU-2017-2782
ALT-PU-2018-1854
CESA-2017_3382
CVE-2017-7843
DLA-1202-1
DSA-4062-1
MGASA-2017-0448
MGASA-2018-0018
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2017:3382
RHSA-2017_3382

Affected Products

Alt Linux
Centos
Firefox
Red Hat