On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2018-06-11T21:00:00

Updated: 2024-08-05T16:12:28.500Z

Reserved: 2017-04-12T00:00:00

Link: CVE-2017-7794

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-06-11T21:29:09.547

Modified: 2019-10-03T00:03:26.223

Link: CVE-2017-7794

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-08-08T00:00:00Z

Links: CVE-2017-7794 - Bugzilla