SB2017030704 - Security bypass in Mozilla Firefox
Published: March 7, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security bypass (CVE-ID: CVE-2017-5400)
The vulnerability allows a remote attacker to bypass implemented security mechanisms.
The vulnerability exists due to an error within asm.js. A remote attacker can perform a JIT-spray technique combined with a heap spray and bypass implemented ASLR and DEP protections.
Successful exploitation of the vulnerability may allow an attacker to leverage exploitation of other remote code execution vulnerabilities.
Remediation
Install update from vendor's website.