The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of "/private/var" that could expose personal or temporary data. This has been updated to not allow access to "/private/var" and its subdirectories. Note: this issue only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mozilla
Published: 2018-06-11T21:00:00
Updated: 2024-08-05T15:04:13.336Z
Reserved: 2017-01-13T00:00:00
Link: CVE-2017-5425
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-06-11T21:29:05.297
Modified: 2024-11-21T03:27:35.697
Link: CVE-2017-5425
Redhat
No data.