CVE-2017-7814: Input Validation
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
Other sources
File downloads encoded with blob: and data: URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious.
— Mozilla
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2017-7814?
CVE-2017-7814 is a vulnerability that allows file downloads encoded with "blob:" and "data:" URL elements to bypass normal file download checks.
What is the severity of CVE-2017-7814?
The severity of CVE-2017-7814 is high (7.8).
Which software versions are affected by CVE-2017-7814?
Ubuntu Firefox versions up to and including 56.0, Firefox ESR versions up to and including 52.4.0, Thunderbird versions up to and including 52.4.0, and various Redhat and Debian Linux versions are affected by CVE-2017-7814.
How can I mitigate CVE-2017-7814?
To mitigate CVE-2017-7814, update your Firefox, Thunderbird, or Linux software to the recommended versions.
Where can I find more information about CVE-2017-7814?
You can find more information about CVE-2017-7814 on Bugzilla, Mozilla's security advisories page, and SecurityFocus.