PT-2018-8427 · Mozilla+1 · Firefox+1

Jordi Chancel

·

Published

2017-07-15

·

Updated

2018-08-13

·

CVE-2017-7770

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 54
Description A mechanism in Firefox for Android allows a malicious site to display a spoofed addressbar when entering fullscreen mode after loading a new tab through JavaScript events. This enables the malicious site to show the location of an arbitrary website instead of the one loaded. Desktop Firefox is unaffected.
Recommendations For versions prior to 54, update to version 54 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1886
CVE-2017-7770

Affected Products

Alt Linux
Firefox