First published: Tue Jan 24 2017(Updated: )
Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potential privilege escalation. This vulnerability affects Firefox < 51.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <51 | 51 |
Firefox | <51.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-5391 has a medium severity rating due to its potential for privilege escalation in Firefox versions prior to 51.
To fix CVE-2017-5391, upgrade Firefox to version 51 or later.
Firefox versions prior to 51 are affected by CVE-2017-5391.
CVE-2017-5391 can potentially be exploited to allow content injection leading to privilege escalation.
There are no known workarounds for CVE-2017-5391 other than updating Firefox to a secure version.