Buffer overflow in Mozilla Firefox - CVE-2017-7845
Published: December 8, 2017
Vulnerability identifier: #VU9593
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2017-7845
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Mozilla
Affected software:
Mozilla Firefox
Mozilla Firefox
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists on Windows systems due to an incorrect value being passed within the library during checks. A remote attacker can trick the victim into visiting a specially crafted website, trigger buffer overlow when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists on Windows systems due to an incorrect value being passed within the library during checks. A remote attacker can trick the victim into visiting a specially crafted website, trigger buffer overlow when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability may result in system compromise.
How to mitigate CVE-2017-7845
Update to version 57.0.2.