Red Hat Bugzilla – Bug 1429782
CVE-2017-5407 Mozilla: Pixel and history stealing via floating-point timing side channel with SVG filters (MFSA 2017-06)
Last modified: 2017-03-14 02:38:40 EDT
Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2017-06/#CVE-2017-5407 Acknowledgements: Name: the Mozilla project Upstream: David Kohlbrenner
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:0461 https://rhn.redhat.com/errata/RHSA-2017-0461.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 5 Via RHSA-2017:0459 https://rhn.redhat.com/errata/RHSA-2017-0459.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Via RHSA-2017:0498 https://rhn.redhat.com/errata/RHSA-2017-0498.html