Lucene search

K
ubuntucveUbuntu.comUB:CVE-2017-7831
HistoryNov 15, 2017 - 12:00 a.m.

CVE-2017-7831

2017-11-1500:00:00
ubuntu.com
ubuntu.com
18

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.002

Percentile

60.0%

A vulnerability where the security wrapper does not deny access to some
exposed properties using the deprecated “exposedProps” mechanism on proxy
objects. These properties should be explicitly unavailable to proxy
objects. This vulnerability affects Firefox < 57.

Notes

Author Note
tyhicks mozjs contains a copy of the SpiderMonkey JavaScript engine
chrisccoulson This is not fixed in mozjs52, but it’s unclear whether it is unaffected or just ignored as https://bugzilla.mozilla.org/show_bug.cgi?id=1392026 is still private and I can’t find a changeset referencing it)
OSVersionArchitecturePackageVersionFilename
ubuntu17.10noarchfirefox< 57.0+build4-0ubuntu0.17.10.5UNKNOWN
ubuntu18.04noarchfirefox< 57.0.1+build2-0ubuntu1UNKNOWN
ubuntu18.10noarchfirefox< 57.0.1+build2-0ubuntu1UNKNOWN
ubuntu19.04noarchfirefox< 57.0.1+build2-0ubuntu1UNKNOWN
ubuntu19.10noarchfirefox< 57.0.1+build2-0ubuntu1UNKNOWN
ubuntu20.04noarchfirefox< 57.0.1+build2-0ubuntu1UNKNOWN
ubuntu20.10noarchfirefox< 57.0.1+build2-0ubuntu1UNKNOWN
ubuntu21.04noarchfirefox< 57.0.1+build2-0ubuntu1UNKNOWN
ubuntu21.10noarchfirefox< 57.0.1+build2-0ubuntu1UNKNOWN
ubuntu22.04noarchfirefox< 57.0.1+build2-0ubuntu1UNKNOWN
Rows per page:
1-10 of 191

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.002

Percentile

60.0%