CVE-2017-5414

medium

Description

The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to information disclosure, such as the operating system or the local account name. This vulnerability affects Firefox < 52 and Thunderbird < 52.

References

https://www.mozilla.org/security/advisories/mfsa2017-09/

https://www.mozilla.org/security/advisories/mfsa2017-05/

https://bugzilla.mozilla.org/show_bug.cgi?id=1319370

http://www.securitytracker.com/id/1037966

http://www.securityfocus.com/bid/96692

Details

Source: Mitre, NVD

Published: 2018-06-11

Updated: 2018-08-02

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium