CVE-2017-5466: XSS
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
Other sources
If a page is loaded from an original site through a hyperlink and contains a redirect to a <code>data:text/html</code> URL with defined <code>Location</code> header; triggering a reload will run the reloaded <code>data:text/html</code> page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5466
Acknowledgements:
Name: the Mozilla project Upstream: Takeshi Terada
— Red Hat
If a page is loaded from an original site through a hyperlink and contains a redirect to a data:text/html URL, triggering a reload will run the reloaded data:text/html page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5433
- CVE-2017-5435
- CVE-2017-5436
- CVE-2017-5461
- CVE-2017-5459
- CVE-2017-5466
- CVE-2017-5434
- CVE-2017-5432
- CVE-2017-5460
- CVE-2017-5438
- CVE-2017-5439
- CVE-2017-5440
- CVE-2017-5441
- CVE-2017-5442
- CVE-2017-5464
- CVE-2017-5443
- CVE-2017-5444
- CVE-2017-5446
- CVE-2017-5447
- CVE-2017-5465
- CVE-2016-10196
- CVE-2017-5454
- CVE-2017-5469
- CVE-2017-5445
- CVE-2017-5449
- CVE-2017-5451
- CVE-2017-5462
- CVE-2017-5467
- CVE-2017-5430
- CVE-2017-5429
- CVE-2017-5448
- CVE-2017-5455
- CVE-2017-5456
- CVE-2017-5450
- CVE-2017-5463
- CVE-2017-5452
- CVE-2017-5453
- CVE-2017-5458
- CVE-2017-5468
Frequently Asked Questions
What is the severity of CVE-2017-5466?
CVE-2017-5466 has been classified as a moderate severity vulnerability.
How do I fix CVE-2017-5466?
To fix CVE-2017-5466, you need to update your Mozilla Thunderbird, Firefox, or Firefox ESR to the latest version available.
Which software versions are affected by CVE-2017-5466?
CVE-2017-5466 affects Mozilla Thunderbird versions prior to 52.1, Firefox ESR versions prior to 52.1, and Firefox versions prior to 53.
What type of vulnerability is CVE-2017-5466?
CVE-2017-5466 is a cross-site scripting (XSS) vulnerability that can allow attackers to execute malicious scripts in users' browsers.
What are the risks associated with CVE-2017-5466?
The risks associated with CVE-2017-5466 include potential unauthorized access to user data and the ability to carry out malicious actions on behalf of the user.