First published: Wed Nov 29 2017(Updated: )
A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which pages a user has in their history. This can allow a malicious website to query user history. Note: This issue only affects Firefox 57. Earlier releases are not affected.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <57.0.1 | 57.0.1 |
<57.0.1 | 57.0.1 | |
Mozilla Firefox | <57.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7844 is a vulnerability in Mozilla Firefox that allows a malicious website to query user history.
Mozilla Firefox versions up to and including 57.0.1 are affected by CVE-2017-7844.
By using a combination of an external SVG image and the coloring of anchor links stored within the image, a malicious website can determine the user's browsing history.
CVE-2017-7844 has a severity level of 6.5 (high).
Upgrade to Mozilla Firefox version 57.0.1 or later to fix the CVE-2017-7844 vulnerability.