CVE-2017-7814
CVE-2017-7814
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
11 jun 2018Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://access.redhat.com/errata/RHSA-2017:2831https://access.redhat.com/errata/RHSA-2017:2885https://bugzilla.mozilla.org/show_bug.cgi?id=1376036https://lists.debian.org/debian-lts-announce/2017/11/msg00000.htmlhttps://security.gentoo.org/glsa/201803-14https://www.debian.org/security/2017/dsa-3987https://www.debian.org/security/2017/dsa-4014https://www.mozilla.org/security/advisories/mfsa2017-21/https://www.mozilla.org/security/advisories/mfsa2017-22/https://www.mozilla.org/security/advisories/mfsa2017-23/http://www.securityfocus.com/bid/101059http://www.securitytracker.com/id/1039465