On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.securitytracker.com/id/1039124 | Third Party Advisory VDB Entry | 
| https://bugzilla.mozilla.org/show_bug.cgi?id=1374281 | Exploit Issue Tracking Vendor Advisory | 
| https://www.mozilla.org/security/advisories/mfsa2017-18/ | Vendor Advisory | 
| http://www.securitytracker.com/id/1039124 | Third Party Advisory VDB Entry | 
| https://bugzilla.mozilla.org/show_bug.cgi?id=1374281 | Exploit Issue Tracking Vendor Advisory | 
| https://www.mozilla.org/security/advisories/mfsa2017-18/ | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    21 Nov 2024, 03:32
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://www.securitytracker.com/id/1039124 - Third Party Advisory, VDB Entry | |
| References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1374281 - Exploit, Issue Tracking, Vendor Advisory | |
| References | () https://www.mozilla.org/security/advisories/mfsa2017-18/ - Vendor Advisory | 
Information
                Published : 2018-06-11 21:29
Updated : 2024-11-21 03:32
NVD link : CVE-2017-7794
Mitre link : CVE-2017-7794
CVE.ORG link : CVE-2017-7794
JSON object : View
Products Affected
                linux
- linux_kernel
mozilla
- firefox
CWE
                
                    
                        
                        CWE-276
                        
            Incorrect Default Permissions
