First published: Tue Aug 08 2017(Updated: )
On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <55.0 | |
Linux Kernel | ||
Firefox | <55 | 55 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7794 is classified as a moderate severity vulnerability affecting Firefox on Linux systems.
To fix CVE-2017-7794, update Mozilla Firefox to version 56 or later.
CVE-2017-7794 affects only Linux operating systems running Firefox version 55 or earlier.
Exploitation of CVE-2017-7794 can allow a compromised content process to truncate files despite restricted access.
Yes, CVE-2017-7794 affects Firefox versions up to and including 55.