Buffer overflow in Firefox ESR - CVE-2017-5373
Published: June 11, 2018 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Affected software
Arch Linux
Gentoo Linux
SUSE Linux
Slackware Linux
firefox-esr (Alpine package)
How to mitigate CVE-2017-5373
firefox-esr (Alpine package) - update to 45.7.0-r0
External References
- http://rhn.redhat.com/errata/RHSA-2017-0190.html
- http://rhn.redhat.com/errata/RHSA-2017-0238.html
- http://www.securityfocus.com/bid/95762
- http://www.securitytracker.com/id/1037693
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1322315%2C1328834%2C1322420%2C1285833%2C1285960%2C1328251%2C1331058%2C1325938%2C1325877
- https://security.gentoo.org/glsa/201702-13
- https://security.gentoo.org/glsa/201702-22
- https://www.debian.org/security/2017/dsa-3771
- https://www.debian.org/security/2017/dsa-3832
- https://www.mozilla.org/security/advisories/mfsa2017-01/
- https://www.mozilla.org/security/advisories/mfsa2017-02/
- https://www.mozilla.org/security/advisories/mfsa2017-03/
Related Security Bulletins
- Buffer overflow in Mozilla Firefox ESR
- SUSE Linux update for MozillaFirefox
- SUSE Linux update for MozillaFirefox
- Buffer overflow in firefox-esr (Alpine package)
- Arch Linux update for thunderbird
- Gentoo update for Mozilla Firefox
- Gentoo update for Mozilla Thunderbird
- Slackware Linux update for mozilla-thunderbird