CVE-2017-7803: High severity thunderbird vulnerability
When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of CSP. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Other sources
When a page’s content security policy (CSP) header contains a sandbox directive other directives are ignored. This results in the incorrect enforcement of CSP directives.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7803
Acknowledgements:
Name: the Mozilla project Upstream: Rhys Enniks
— Red Hat
When a page’s content security policy (CSP) header contains a sandbox directive, other directives are ignored. This results in the incorrect enforcement of CSP.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-7800
- CVE-2017-7801
- CVE-2017-7809
- CVE-2017-7784
- CVE-2017-7802
- CVE-2017-7785
- CVE-2017-7786
- CVE-2017-7753
- CVE-2017-7787
- CVE-2017-7807
- CVE-2017-7792
- CVE-2017-7804
- CVE-2017-7791
- CVE-2017-7782
- CVE-2017-7803
- CVE-2017-7779
- CVE-2017-7798
- CVE-2017-7806
- CVE-2017-7808
- CVE-2017-7781
- CVE-2017-7794
- CVE-2017-7799
- CVE-2017-7783
- CVE-2017-7788
- CVE-2017-7789
- CVE-2017-7790
- CVE-2017-7796
- CVE-2017-7797
- CVE-2017-7780
Frequently Asked Questions
What is the severity of CVE-2017-7803?
CVE-2017-7803 has a moderate severity level due to the potential for incorrect enforcement of content security policies.
How do I fix CVE-2017-7803?
To fix CVE-2017-7803, update your Firefox or Thunderbird client to versions 52.3 or higher.
Which software versions are affected by CVE-2017-7803?
CVE-2017-7803 affects Thunderbird versions below 52.3, Firefox ESR versions below 52.3, and Firefox versions below 55.
Is there a specific vendor associated with CVE-2017-7803?
CVE-2017-7803 is associated with Mozilla, affecting their Firefox and Thunderbird products.
What are the potential consequences of CVE-2017-7803?
The potential consequences of CVE-2017-7803 include security vulnerabilities that may allow unauthorized content execution due to improper CSP enforcement.