First published: Thu Sep 28 2017(Updated: )
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 131.0.2-2 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.3.1esr-1~deb11u1 115.14.0esr-1~deb12u1 128.3.1esr-1~deb12u1 128.3.0esr-2 128.3.1esr-2 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:115.16.0esr-1~deb11u1 1:115.12.0-1~deb12u1 1:115.16.0esr-1~deb12u1 1:128.2.0esr-1 1:128.3.0esr-1 | |
Thunderbird | <52.4 | 52.4 |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.5 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
Firefox | <56.0 | |
Firefox ESR | <52.4.0 | |
Thunderbird | <52.4.0 | |
Debian | =7.0 | |
Debian | =8.0 | |
Debian | =9.0 | |
Firefox | <56 | 56 |
Firefox ESR | <52.4 | 52.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7814 is a vulnerability that allows file downloads encoded with "blob:" and "data:" URL elements to bypass normal file download checks.
The severity of CVE-2017-7814 is high (7.8).
Ubuntu Firefox versions up to and including 56.0, Firefox ESR versions up to and including 52.4.0, Thunderbird versions up to and including 52.4.0, and various Redhat and Debian Linux versions are affected by CVE-2017-7814.
To mitigate CVE-2017-7814, update your Firefox, Thunderbird, or Linux software to the recommended versions.
You can find more information about CVE-2017-7814 on Bugzilla, Mozilla's security advisories page, and SecurityFocus.