VDB
BDU%3A2020-05847
BDU%3A2020-05847
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость функции PFileSystemRequestConstructor браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная c обходом защиты доступа к файловой системе в песочнице, позволяющая нарушителю получить доступ к защищаемой информации
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «РусБИТех-Астра», Red Hat Inc., Canonical Ltd., АО «ИВК», Novell Inc., Mozilla Corp. | Astra Linux Special Edition (запись в едином реестре российских программ №369), Red Hat Enterprise Linux, Ubuntu, Альт Линукс СПТ (запись в едином реестре российских программ №9), OpenSUSE Leap, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Software Development Kit, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Server for Raspberry Pi, Firefox, Thunderbird, Firefox ESR |
Timeline
- Dec 28, 2020 CVE Published
- Jan 12, 2021 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-5454 url
- https://www.mozilla.org/security/advisories/mfsa2017-12/ url
- https://www.suse.com/security/cve/CVE-2017-5454/ url
- https://wiki.astralinux.ru/pages/viewpage.action?pageId=1212483 url
- https://cve.basealt.ru/ url
- https://wiki.astralinux.ru/astra-linux-se15-bulletin-20201201SE15 url
- https://ubuntu.com/security/notices/USN-3260-1?_ga=2.91217818.1630830267.1608209597-1543702552.1605094901 url
- https://www.mozilla.org/security/advisories/mfsa2017-10/ advisory
- https://www.mozilla.org/security/advisories/mfsa2017-13/ advisory
- https://access.redhat.com/security/cve/cve-2017-5454 advisory
- https://ubuntu.com/security/notices/USN-3278-1?_ga=2.91217818.1630830267.1608209597-1543702552.1605094901 advisory