Red Hat Bugzilla – Bug 1479209
CVE-2017-7791 Mozilla: Spoofing following page navigation with data: protocol and modal alerts (MFSA 2017-19)
Last modified: 2017-08-24 03:33:59 EDT
The `data:` protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, allowing for the spoofing of the origin of the iframe content. External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7791 Acknowledgements: Name: the Mozilla project Upstream: Jose María Acuña
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Red Hat Enterprise Linux 6 Via RHSA-2017:2456 https://access.redhat.com/errata/RHSA-2017:2456
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Via RHSA-2017:2534 https://access.redhat.com/errata/RHSA-2017:2534