CVE-2017-7843 (retired)

Priority
Description
When Private Browsing mode is used, it is possible for a web worker to
write persistent data to IndexedDB and fingerprint a user uniquely.
IndexedDB should not be available in Private Browsing mode and this stored
data will persist across multiple private browsing mode sessions because it
is not cleared when exiting. This vulnerability affects Firefox ESR <
52.5.2 and Firefox < 57.0.1.
Assigned-to
chrisccoulson
Package
Upstream:released (57.0.1)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (57.0.1+build2-0ubuntu0.14.04.1)
Ubuntu 16.04 LTS (Xenial Xerus):released (57.0.1+build2-0ubuntu0.16.04.1)
Ubuntu 18.04 LTS (Bionic Beaver):released (57.0.1+build2-0ubuntu1)
Ubuntu 18.10 (Cosmic Cuttlefish):released (57.0.1+build2-0ubuntu1)
More Information

Updated: 2019-03-26 12:26:29 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)