First published: Tue Mar 07 2017(Updated: )
If a malicious site uses the view-source: protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the hyperlink is selected. This was fixed by no longer making view-source: linkable.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <52 | 52 |
Thunderbird | <52 | 52 |
Firefox | <52.0 | |
Thunderbird | <52.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-5422 has been classified as a low-severity vulnerability that can cause a non-exploitable browser crash.
To address CVE-2017-5422, users should upgrade to a version of Firefox or Thunderbird that is 52.0 or later.
CVE-2017-5422 affects Mozilla Firefox and Thunderbird versions prior to 52.0.
CVE-2017-5422 involves a malicious site exploiting the view-source protocol to trigger a crash in the browser.
Yes, the vulnerability has been resolved by preventing the view-source protocol from being linkable.