SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-5426

On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running filter which is…

MEDIUM 5.3EPSS 1.44%

Does this matter?

Lower severity and a low EPSS score (1.44%). Track it; it rarely justifies an emergency change on its own.

Description

On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running filter which is typically weak compared to the sandbox. Note: this issue only affects Linux. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
1.44% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-732
Affected
mozilla/firefox · mozilla/thunderbird
Source
security@mozilla.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.