CVE-2017-7814

Priority
Medium
Description
File downloads encoded with "blob:" and "data:" URL elements bypassed
normal file download checks though the Phishing and Malware Protection
feature and its block lists of suspicious sites and files. This would allow
malicious sites to lure users into downloading executables that would
otherwise be detected as suspicious. This vulnerability affects Firefox <
56, Firefox ESR < 52.4, and Thunderbird < 52.4.
References
Assigned-to
chrisccoulson
Package
Priority: Low
Upstream:released (52.4.0)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (1:52.4.0+build1-0ubuntu0.14.04.2)
Ubuntu 16.04 LTS (Xenial Xerus):released (1:52.4.0+build1-0ubuntu0.16.04.2)
Ubuntu 17.10 (Artful Aardvark):released (1:52.4.0+build1-0ubuntu2)
Ubuntu 18.04 LTS (Bionic Beaver):released (1:52.4.0+build1-0ubuntu2)
Ubuntu 18.10 (Cosmic Cuttlefish):released (1:52.4.0+build1-0ubuntu2)
Package
Upstream:released (56.0)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (56.0+build6-0ubuntu0.14.04.1)
Ubuntu 16.04 LTS (Xenial Xerus):released (56.0+build6-0ubuntu0.16.04.1)
Ubuntu 17.10 (Artful Aardvark):released (56.0+build6-0ubuntu1)
Ubuntu 18.04 LTS (Bionic Beaver):released (56.0+build6-0ubuntu1)
Ubuntu 18.10 (Cosmic Cuttlefish):released (56.0+build6-0ubuntu1)
More Information

Updated: 2018-06-26 05:02:44 UTC (commit 7799c934cca373482531a7b00e4dfe82302ceae5)