CVE-2017-7847: Infoleak
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2017-7847?
CVE-2017-7847 is a vulnerability that allows crafted CSS in an RSS feed to leak and reveal local path strings, which may contain the user name.
Which software is affected by CVE-2017-7847?
Thunderbird versions prior to 52.5.2 are affected by CVE-2017-7847.
How severe is CVE-2017-7847?
CVE-2017-7847 has a severity score of 4.3 (high severity).
How can I fix CVE-2017-7847?
To fix CVE-2017-7847, you should upgrade Thunderbird to version 52.6.0 or higher.
Where can I find more information about CVE-2017-7847?
You can find more information about CVE-2017-7847 at the following references: [Link 1](https://bugzilla.mozilla.org/show_bug.cgi?id=1411708), [Link 2](https://www.mozilla.org/en-US/security/advisories/mfsa2017-30/), [Link 3](http://www.securityfocus.com/bid/102258).