[MFSA-2017-27] Security vulnerabilities fixed in Firefox 57.0.1

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 2
  • CVE-2017-7843: Web worker in Private Browsing mode can write IndexedDB data (high)
    When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting.

  • CVE-2017-7844: Visited history information leak through SVG image (high)
    A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which pages a user has in their history. This can allow a malicious website to query user history.
    Note: This issue only affects Firefox 57. Earlier releases are not affected.

Package Affected Version
pkg:mozilla/Firefox < 57.0.1
Package Fixed Version
pkg:mozilla/Firefox = 57.0.1
(6 years ago)
(6 years ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:mozilla/Firefox Firefox < 57.0.1
Fixed pkg:mozilla/Firefox Firefox = 57.0.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date