PT-2017-4016 · Mozilla+2 · Firefox+2
Frederik Braun
·
Published
2017-06-13
·
Updated
2024-12-12
·
CVE-2017-7799
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 55
Description
The issue is related to the implementation of the WebRTC mechanism in Mozilla Firefox, which fails to protect the structure of web pages. This could potentially allow a remote attacker to conduct cross-site scripting (XSS) attacks. The vulnerability is difficult to exploit because the data is supplied by WebRTC usage and is not under third-party control.
Recommendations
For versions prior to 55, update to version 55 or later to resolve the issue. As a temporary workaround, consider restricting access to the "about:webrtc" page until a patch is available. Avoid using the
innerHTML property in the affected page to minimize the risk of exploitation.Exploit
Fix
Command Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Firefox
Ubuntu