The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. This allows for privilege escalation as the replaced libcurl code will run with Firefox's privileges. Note: This attack requires an attacker have local system access and only affects OS X and Linux. Windows systems are not affected. This vulnerability affects Firefox < 57.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2017-24/ | vendor advisory |
http://www.securityfocus.com/bid/101832 | third party advisory vdb entry |
http://www.securitytracker.com/id/1039803 | third party advisory vdb entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=1401339 | issue tracking permissions required |