4.6
CVSSv2

CVE-2017-7836

Published: 11/06/2018 Updated: 03/10/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. This allows for privilege escalation as the replaced libcurl code will run with Firefox's privileges. Note: This attack requires an attacker have local system access and only affects OS X and Linux. Windows systems are not affected. This vulnerability affects Firefox < 57.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Mozilla Foundation Security Advisory 2017-24 Security vulnerabilities fixed in Firefox 57 Announced November 14, 2017 Impact critical Products Firefox Fixed in Firefox 57 ...
The "pingsender" executable used by the Firefox Health Report before 570 dynamically loads a system copy of libcurl, which an attacker could replace This allows for privilege escalation as the replaced libcurl code will run with Firefox's privileges This attack requires an attacker have local system access ...