Description
If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example.com"), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service. This vulnerability affects Firefox < 55.
In plain language
AI Worth attentionCVE-2017-7783 can let a remote attacker freeze or crash Firefox by sending it a specially crafted website link with an extremely long username; most small businesses should act only if staff use a Firefox version older than 55.
In Firefox, a remote attacker can trigger a denial of service by using a crafted URL with an excessively long username in a user:pass@ URL, causing the browser’s security prompt/modal to hang or crash (Firefox < 55.0).
What to do now
- Check each workstation/server running Firefox and note the Firefox version.
- If any Firefox version is older than 55, update Firefox to 55.0 (or later) right away.
- After updating, try opening a normal login URL and confirm the browser no longer hangs when security prompts appear.
- If you can’t update immediately, limit exposure by avoiding clicking or loading untrusted links that include user:pass@ style URLs.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-7783 and every CVE in our database. Create a free account — no credit card required.
Create Free Account