PT-2017-3742 · Mozilla+5 · Firefox+8

Holger Fuhrmannek

+1

·

Publicado

2017-05-29

·

Atualizado

2024-06-15

·

CVE-2017-7778

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Graphite 2 versions prior to 1.3.10 Mozilla Firefox versions prior to 54 Mozilla Firefox ESR versions prior to 52.2 Thunderbird versions prior to 52.2
Description: The issue is related to the lz4::decompress function in the Graphite 2 library, which is used by Mozilla Firefox and Mozilla Firefox ESR. It involves an out-of-bounds buffer write in memory. Exploitation of this issue can allow a remote attacker to execute arbitrary code or cause a denial of service. Additionally, there are other security issues in the Graphite 2 library, including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory.
Recommendations: For Graphite 2 versions prior to 1.3.10, update to version 1.3.10 or later. For Mozilla Firefox versions prior to 54, update to version 54 or later. For Mozilla Firefox ESR versions prior to 52.2, update to version 52.2 or later. For Thunderbird versions prior to 52.2, update to version 52.2 or later.

Correção

Buffer Overflow

Out of bounds Read

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1665
ALT-PU-2017-1770
ALT-PU-2017-1777
ALT-PU-2017-1886
ALT-PU-2018-1854
BDU:2019-00230
CESA-2017_1440
CESA-2017_1561
CESA-2017_1793
CVE-2017-7778
DLA-1007-1
DLA-1013-1
DLA-991-1
DSA-3881-1
DSA-3894-1
DSA-3918-1
MGASA-2017-0178
MGASA-2017-0180
MGASA-2017-0217
MGASA-2018-0018
OPENSUSE-SU-2017:1579-1
OPENSUSE-SU-2017_1620-1
OPENSUSE-SU-2024:10601-1
RHSA-2017:1440
RHSA-2017:1561
RHSA-2017:1793
RHSA-2017_1440
RHSA-2017_1561
RHSA-2017_1793
SUSE-SU-2017:1669-1
SUSE-SU-2017:2235-1
USN-3315-1
USN-3321-1
USN-3398-1

Produtos afetados

Alt Linux
Centos
Graphite 2
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Ubuntu