UBUNTU-CVE-2017-16541
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-16541
Summary:
Details: Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.
References: https://ubuntu.com/security/CVE-2017-16541, https://trac.torproject.org/projects/tor/ticket/24052, https://blog.torproject.org/tor-browser-709-released, https://www.mozilla.org/en-US/security/advisories/mfsa2018-20/#CVE-2017-16541, https://www.mozilla.org/en-US/security/advisories/mfsa2018-21/#CVE-2017-16541, https://www.mozilla.org/en-US/security/advisories/mfsa2018-25/#CVE-2017-16541, https://www.cve.org/CVERecord?id=CVE-2017-16541
Affected packages
Package
Name: firefox
Purl: pkg:deb/ubuntu/[email protected]+build2-0ubuntu0.16.04.3?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
