Information disclosure in Firefox ESR and Mozilla Firefox - CVE-2017-5445
Published: April 19, 2017
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to an error when parsing application/http-index-format format content where uninitialized values are used to create an array. A remote attacker can read portions of uninitialized memory.
Successful exploitation of the vulnerability may allow an attacker to gain access to potentially sensitive information.
Affected software
Mozilla Firefox
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for x86_64
SUSE Linux
Ubuntu
Mozilla Thunderbird
How to mitigate CVE-2017-5445
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Mozilla Thunderbird
- Red Hat update for Mozilla Thunderbird
- SUSE Linux update for MozillaFirefox
- Arch Linux update for firefox
- Ubuntu update for Firefox
- Ubuntu update for Firefox
- Gentoo update for Mozilla Firefox
- SUSE Linux update for MozillaFirefox