First published: Thu Sep 28 2017(Updated: )
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <52.4 | 52.4 |
Mozilla Thunderbird | <52.4 | 52.4 |
Mozilla Firefox | <56 | 56 |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Server Aus | =7.4 | |
Redhat Enterprise Linux Server Eus | =7.4 | |
Redhat Enterprise Linux Server Eus | =7.5 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Mozilla Firefox | <56.0 | |
Mozilla Firefox ESR | <52.4.0 | |
Mozilla Thunderbird | <52.4.0 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
debian/firefox | 131.0.2-2 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.3.1esr-1~deb11u1 115.14.0esr-1~deb12u1 128.3.1esr-1~deb12u1 128.3.0esr-2 128.3.1esr-2 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:115.16.0esr-1~deb11u1 1:115.12.0-1~deb12u1 1:115.16.0esr-1~deb12u1 1:128.2.0esr-1 1:128.3.0esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7814 is a vulnerability that allows file downloads encoded with "blob:" and "data:" URL elements to bypass normal file download checks.
The severity of CVE-2017-7814 is high (7.8).
Ubuntu Firefox versions up to and including 56.0, Firefox ESR versions up to and including 52.4.0, Thunderbird versions up to and including 52.4.0, and various Redhat and Debian Linux versions are affected by CVE-2017-7814.
To mitigate CVE-2017-7814, update your Firefox, Thunderbird, or Linux software to the recommended versions.
You can find more information about CVE-2017-7814 on Bugzilla, Mozilla's security advisories page, and SecurityFocus.