Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2017-06/#CVE-2017-5407 Acknowledgements: Name: the Mozilla project Upstream: David Kohlbrenner
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:0461 https://rhn.redhat.com/errata/RHSA-2017-0461.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 5 Via RHSA-2017:0459 https://rhn.redhat.com/errata/RHSA-2017-0459.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Via RHSA-2017:0498 https://rhn.redhat.com/errata/RHSA-2017-0498.html