CVE-2017-7820 (retired)

Priority
Description
The "instanceof" operator can bypass the Xray wrapper mechanism. When
called on web content from the browser itself or an extension the web
content can provide its own result for that operator, possibly tricking the
browser or extension into mishandling the element. This vulnerability
affects Firefox < 56.
Assigned-to
chrisccoulson
Package
Upstream:released (56.0)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (56.0+build6-0ubuntu0.14.04.1)
Ubuntu 16.04 LTS (Xenial Xerus):released (56.0+build6-0ubuntu0.16.04.1)
Ubuntu 18.04 LTS (Bionic Beaver):released (56.0+build6-0ubuntu1)
Ubuntu 18.10 (Cosmic Cuttlefish):released (56.0+build6-0ubuntu1)
More Information

Updated: 2019-03-26 12:26:28 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)