Vulnerability Name: | CVE-2017-7796 (CCN-130184) | ||||||||||||||||||||||||||||
Assigned: | 2017-08-08 | ||||||||||||||||||||||||||||
Published: | 2017-08-08 | ||||||||||||||||||||||||||||
Updated: | 2018-08-09 | ||||||||||||||||||||||||||||
Summary: | On Windows systems, the logger run by the Windows updater deletes the file "update.log" before it runs in order to write a new log of that name. The path to this file is supplied at the command line to the updater and could be used in concert with another local exploit to delete a different file named "update.log" instead of the one intended. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Firefox < 55. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.7 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N) 4.1 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
5.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 3.3 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-7796 Source: SECTRACK Type: Third Party Advisory, VDB Entry 1039124 Source: CONFIRM Type: Issue Tracking, Patch, Vendor Advisory https://bugzilla.mozilla.org/show_bug.cgi?id=1234401 Source: XF Type: UNKNOWN firefox-cve20177796-file-deletion(130184) Source: CCN Type: Mozilla Foundation Security Advisory 2017-18 Security vulnerabilities fixed in Firefox 55 Source: CONFIRM Type: Vendor Advisory https://www.mozilla.org/security/advisories/mfsa2017-18/ | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |