The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when opening a malicious page with the style editor tool. This vulnerability affects Firefox ESR < 52.3 and Firefox < 55.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2017-19/ | vendor advisory |
http://www.securityfocus.com/bid/100198 | third party advisory vdb entry |
https://www.mozilla.org/security/advisories/mfsa2017-18/ | vendor advisory |
https://access.redhat.com/errata/RHSA-2017:2456 | third party advisory vendor advisory |
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1371586%2C1372112 | vendor advisory issue tracking |
http://www.securitytracker.com/id/1039124 | third party advisory vdb entry |
https://www.debian.org/security/2017/dsa-3928 | third party advisory vendor advisory |