Buffer overflow in Mozilla Firefox - CVE-2017-7845
Published: December 8, 2017
Vulnerability identifier: #VU9593
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7845
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists on Windows systems due to an incorrect value being passed within the library during checks. A remote attacker can trick the victim into visiting a specially crafted website, trigger buffer overlow when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists on Windows systems due to an incorrect value being passed within the library during checks. A remote attacker can trick the victim into visiting a specially crafted website, trigger buffer overlow when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Mozilla Firefox
Mozilla Thunderbird
firefox-esr (Alpine package)
Mozilla Thunderbird
firefox-esr (Alpine package)
How to mitigate CVE-2017-7845
Update to version 57.0.2.
firefox-esr (Alpine package) - update to 52.5.2-r0