CVE-2017-5407: Infoleak
Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5400
- CVE-2017-5401
- CVE-2017-5402
- CVE-2017-5404
- CVE-2017-5407
- CVE-2017-5410
- CVE-2017-5408
- CVE-2017-5405
- CVE-2017-5398
- CVE-2017-5403
- CVE-2017-5406
- CVE-2017-5411
- CVE-2017-5412
- CVE-2017-5413
- CVE-2017-5414
- CVE-2017-5416
- CVE-2017-5425
- CVE-2017-5426
- CVE-2017-5418
- CVE-2017-5419
- CVE-2017-5421
- CVE-2017-5422
- CVE-2017-5399
- CVE-2017-5409
- CVE-2017-5415
- CVE-2017-5417
- CVE-2017-5427
- CVE-2017-5420
Frequently Asked Questions
What is the severity of CVE-2017-5407?
CVE-2017-5407 is classified as a moderate severity vulnerability.
How do I fix CVE-2017-5407?
To fix CVE-2017-5407, upgrade Mozilla Firefox and Mozilla Thunderbird to the latest versions available.
Which versions are affected by CVE-2017-5407?
CVE-2017-5407 affects Mozilla Firefox versions up to 52.0 and Mozilla Thunderbird versions up to 52.0.
What kind of information can be leaked through CVE-2017-5407?
CVE-2017-5407 can potentially leak pixel values, allowing attackers to extract history information and read text values across domains.
Does CVE-2017-5407 violate the same-origin policy?
Yes, CVE-2017-5407 violates the same-origin policy, leading to information disclosure vulnerabilities.