Buffer overflow in Mozilla Firefox - CVE-2017-7845

 

Buffer overflow in Mozilla Firefox - CVE-2017-7845

Published: December 8, 2017


Vulnerability identifier: #VU9593
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7845
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists on Windows systems due to an incorrect value being passed within the library during checks. A remote attacker can trick the victim into visiting a specially crafted website, trigger buffer overlow when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content and execute arbitrary code with privileges of the current user.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

Mozilla Firefox
Mozilla Thunderbird
firefox-esr (Alpine package)

How to mitigate CVE-2017-7845

Update to version 57.0.2.

firefox-esr (Alpine package) - update to 52.5.2-r0

External References

Related Security Bulletins