CVE-2017-5425: Infoleak
The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of /private/var that could expose personal or temporary data. This has been updated to not allow access to /private/var and its subdirectories. Note: this issue only affects OS X. Other operating systems are not affected.
Other sources
The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of "/private/var" that could expose personal or temporary data. This has been updated to not allow access to "/private/var" and its subdirectories. Note: this issue only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5400
- CVE-2017-5401
- CVE-2017-5402
- CVE-2017-5403
- CVE-2017-5404
- CVE-2017-5406
- CVE-2017-5407
- CVE-2017-5410
- CVE-2017-5411
- CVE-2017-5409
- CVE-2017-5408
- CVE-2017-5412
- CVE-2017-5413
- CVE-2017-5414
- CVE-2017-5415
- CVE-2017-5416
- CVE-2017-5417
- CVE-2017-5425
- CVE-2017-5426
- CVE-2017-5427
- CVE-2017-5418
- CVE-2017-5419
- CVE-2017-5420
- CVE-2017-5405
- CVE-2017-5421
- CVE-2017-5422
- CVE-2017-5399
- CVE-2017-5398
Frequently Asked Questions
What is the severity of CVE-2017-5425?
The severity of CVE-2017-5425 is classified as moderate due to its potential to expose personal data.
How do I fix CVE-2017-5425?
To fix CVE-2017-5425, users should update Mozilla Thunderbird or Firefox to version 52.0 or later.
Which versions of software are affected by CVE-2017-5425?
CVE-2017-5425 affects Mozilla Thunderbird versions up to 52 and Firefox versions up to 52.
On which operating system is CVE-2017-5425 a concern?
CVE-2017-5425 is a concern primarily on macOS systems.
What type of data could be exposed due to CVE-2017-5425?
CVE-2017-5425 could expose personal or temporary data from subdirectories within /private/var.