CVE Database
/

CVE-2017-7836

Back to search

CVE-2017-7836

Published: Jun 11, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. This allows for privilege escalation as the replaced libcurl code will run with Firefox's privileges. Note: This attack requires an attacker have local system access and only affects OS X and Linux. Windows systems are not affected. This vulnerability affects Firefox < 57.

VendorProductVersions

Mozilla

Firefox

affected
unspecified - < 57

References

101832
vdb-entry
x_refsource_BID
1039803
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now