The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allowing certificate content to be saved in unsafe locations with an arbitrary filename. This vulnerability affects Firefox < 51.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 11, 2018 |
| Freebsd | — | Upgrade seamonkeyUpgrade linux-firefoxUpgrade firefox-esrUpgrade firefoxUpgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade libxulUpgrade thunderbird | Jan 25, 2017 | Jan 24, 2017 |
| Mfsa2017 01 | — | Upgrade to Mozilla Firefox version 51.0 | Jul 12, 2018 | Jun 11, 2018 |
| Suse | — | Upgrade mozillafirefox-develUpgrade mozillafirefox-translations-otherUpgrade mozillafirefox-translations-commonUpgrade mozillafirefox | Feb 2, 2017 | Jan 24, 2017 |
| Ubuntu | — | Upgrade firefox | Jan 28, 2017 | Jan 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub