CVE-2017-5454

Priority
Description
A mechanism to bypass file system access protections in the sandbox to use
the file picker to access different files than those selected in the file
picker through the use of relative paths. This allows for read only access
to the local file system. This vulnerability affects Thunderbird < 52.1,
Firefox ESR < 52.1, and Firefox < 53.
Assigned-to
chrisccoulson
Package
Upstream:released (53.0)
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was ignored)
Ubuntu 14.04 LTS (Trusty Tahr):released (53.0+build6-0ubuntu0.14.04.1)
Ubuntu 16.04 LTS (Xenial Xerus):released (53.0+build6-0ubuntu0.16.04.1)
Package
Priority: Low
Upstream:released (52.1.1)
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needs-triage)
Ubuntu 14.04 LTS (Trusty Tahr):released (1:52.1.1+build1-0ubuntu0.14.04.1)
Ubuntu 16.04 LTS (Xenial Xerus):released (1:52.1.1+build1-0ubuntu0.16.04.1)
More Information

Updated: 2019-01-14 22:30:32 UTC (commit 51f9b73af244ba86b9321e46e526586c25a8e060)