PT-2017-3740 · Mozilla+5 · Firefox Esr+7
Holger Fuhrmannek
+1
·
Publicado
2017-05-29
·
Atualizado
2019-04-15
·
CVE-2017-7772
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Graphite 2 versions prior to 54
Mozilla Firefox versions prior to 54
Mozilla Firefox ESR versions prior to 54
Description:
The issue is caused by a heap-based buffer overflow in the lz4::decompress function of the Graphite 2 library. This can be exploited by a remote attacker to cause a denial of service or execute arbitrary code.
Recommendations:
For Graphite 2 versions prior to 54, update to version 54 or later to resolve the issue.
For Mozilla Firefox versions prior to 54, update to version 54 or later to resolve the issue.
For Mozilla Firefox ESR versions prior to 54, update to version 54 or later to resolve the issue.
Exploit
Correção
Heap Based Buffer Overflow
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Graphite 2
Firefox
Firefox Esr
Red Hat
Suse
Ubuntu