CVE-2017-7791: Input Validation
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Other sources
On pages containing an iframe, the data: protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content.
The data: protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, allowing for the spoofing of the origin of the iframe content.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7791
Acknowledgements:
Name: the Mozilla project Upstream: Jose María Acuña
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-7800
- CVE-2017-7801
- CVE-2017-7809
- CVE-2017-7784
- CVE-2017-7802
- CVE-2017-7785
- CVE-2017-7786
- CVE-2017-7753
- CVE-2017-7787
- CVE-2017-7807
- CVE-2017-7792
- CVE-2017-7804
- CVE-2017-7791
- CVE-2017-7782
- CVE-2017-7803
- CVE-2017-7779
- CVE-2017-7798
- CVE-2017-7806
- CVE-2017-7808
- CVE-2017-7781
- CVE-2017-7794
- CVE-2017-7799
- CVE-2017-7783
- CVE-2017-7788
- CVE-2017-7789
- CVE-2017-7790
- CVE-2017-7796
- CVE-2017-7797
- CVE-2017-7780
Frequently Asked Questions
What is the severity of CVE-2017-7791?
The severity of CVE-2017-7791 is classified as high due to its potential to spoof modal alerts over arbitrary domains.
How do I fix CVE-2017-7791?
To fix CVE-2017-7791, upgrade to Thunderbird version 52.3 or higher, Firefox version 55 or higher, or Firefox ESR version 52.3 or higher.
Which versions of software are affected by CVE-2017-7791?
CVE-2017-7791 affects Thunderbird versions earlier than 52.3, Firefox versions earlier than 55, and Firefox ESR versions earlier than 52.3.
Can CVE-2017-7791 be exploited remotely?
Yes, CVE-2017-7791 can be exploited remotely due to its ability to spoof alerts over different domains.
What types of applications are impacted by CVE-2017-7791?
CVE-2017-7791 impacts Mozilla applications including Thunderbird, Firefox, and Firefox ESR.