CVE-2017-5409

NameCVE-2017-5409
DescriptionThe Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 45.8 and Firefox < 52.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitylow

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
firefox (PTS)sid73.0.1-1fixed
firefox-esr (PTS)jessie52.8.1esr-1~deb8u1fixed
jessie (security)68.5.0esr-1~deb8u1fixed
stretch68.4.1esr-1~deb9u1fixed
stretch (security)68.5.0esr-1~deb9u1fixed
buster68.4.1esr-1~deb10u1fixed
buster (security)68.5.0esr-1~deb10u1fixed
bullseye, sid68.5.0esr-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
firefoxsource(unstable)(not affected)
firefox-esrsource(unstable)(not affected)

Notes

- firefox <not-affected> (Only Firefox on Windows)
- firefox-esr <not-affected> (Only Firefox on Windows)
https://www.mozilla.org/en-US/security/advisories/mfsa2017-05/#CVE-2017-5409
https://www.mozilla.org/en-US/security/advisories/mfsa2017-06/#CVE-2017-5409

Search for package or bug name: Reporting problems