Vulnerability CVE-2017-5422: Information
Description
If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the hyperlink is selected. This was fixed by no longer making "view-source:" linkable. This vulnerability affects Firefox < 52 and Thunderbird < 52.
Severity: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Fixed packages
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://www.mozilla.org/security/advisories/mfsa2017-09/ |
|
https://www.mozilla.org/security/advisories/mfsa2017-05/ |
|
https://bugzilla.mozilla.org/show_bug.cgi?id=1295002 |
|
1037966 |
|
96692 |
|