ZeroHour

CVE-2017-7794

PoC
CVSS 3.0
7.8 high
EPSS
<1%p27
Published
()
Modified
Description

On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.

Vendors
mozilla
Products
firefox
Weakness
CWE-276
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.