SB2017030704 - Security bypass in Mozilla Firefox



SB2017030704 - Security bypass in Mozilla Firefox

Published: March 7, 2017

Security Bulletin ID SB2017030704
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security bypass (CVE-ID: CVE-2017-5400)

The vulnerability allows a remote attacker to bypass implemented security mechanisms.

The vulnerability exists due to an error within asm.js. A remote attacker can perform a JIT-spray technique combined with a heap spray and bypass implemented ASLR and DEP protections.

Successful exploitation of the vulnerability may allow an attacker to leverage exploitation of other remote code execution vulnerabilities.


Remediation

Install update from vendor's website.