~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2017-5417

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2017-03-07
2
 
Candidate: CVE-2017-5417
3
 
PublicDate: 2018-06-11
4
 
References: 
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5417
6
 
 https://www.mozilla.org/en-US/security/advisories/mfsa2017-05/#CVE-2017-5417
7
 
 https://usn.ubuntu.com/usn/usn-3216-1
8
 
Description:
9
 
 When dragging content from the primary browser pane to the addressbar on a
10
 
 malicious site, it is possible to change the addressbar so that the
11
 
 displayed location following navigation does not match the URL of the newly
12
 
 loaded page. This allows for spoofing attacks. This vulnerability affects
13
 
 Firefox < 52.
14
 
Ubuntu-Description: 
15
 
Notes: 
16
 
Bugs: 
17
 
Priority: medium
18
 
Discovered-by:
19
 
Assigned-to: chrisccoulson
20
 
 
21
 
Patches_firefox: 
22
 
upstream_firefox: released (52.0)
23
 
precise_firefox: released (52.0+build2-0ubuntu0.12.04.1)
24
 
trusty_firefox: released (52.0+build2-0ubuntu0.14.04.1)
25
 
vivid/ubuntu-core_firefox: DNE
26
 
vivid/stable-phone-overlay_firefox: DNE
27
 
xenial_firefox: released (52.0+build2-0ubuntu0.16.04.1)
28
 
yakkety_firefox: released (52.0+build2-0ubuntu0.16.10.1)
29
 
zesty_firefox: released (52.0.1+build2-0ubuntu1)
30
 
devel_firefox: not-affected (52.0.1+build2-0ubuntu1)