ZeroHour

CVE-2017-5397

CVSS 3.0
9.8 critical
EPSS
3%p87
Published
()
Modified
Description

The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for the possibility of an installed malicious application or tools with write access to the file system to replace files used by Firefox with their own versions. This vulnerability affects Firefox < 51.0.3.

Vendors
mozilla
Products
firefox
Weakness
CWE-829
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.