CVE-2017-7794

Source
https://cve.org/CVERecord?id=CVE-2017-7794
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7794.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-7794
Downstream
Related
Published
2018-06-11T21:29:09.547Z
Modified
2026-03-14T14:19:47.014007Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "55.0"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7794.json"