First published: Tue Jan 24 2017(Updated: )
The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on a "<track>" tag refers to a file that does not exist if the source page is loaded locally. This vulnerability affects Firefox < 51.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <51 | 51 |
Firefox | <51.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-5387 has a moderate severity level due to its potential for information disclosure.
To fix CVE-2017-5387, upgrade to Mozilla Firefox version 51 or later.
CVE-2017-5387 affects all versions of Mozilla Firefox prior to version 51.
The main impact of CVE-2017-5387 is the unauthorized disclosure of local file existence.
There are no known effective workarounds to mitigate CVE-2017-5387 aside from updating Firefox.