Memory leak in Mozilla Thunderbird - CVE-2017-7847

 

Memory leak in Mozilla Thunderbird - CVE-2017-7847

Published: December 25, 2017


Vulnerability identifier: #VU9732
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7847
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The vulnerability exists due to leak of local path string from specially crafted CSS and RSS feed. A remote attacker can reveal local path strings, which may contain user name.


Affected software

Mozilla Thunderbird
Debian Linux
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power
SUSE Linux
Opensuse

How to mitigate CVE-2017-7847

Update to version 52.5.2.


External References

Related Security Bulletins