PT-2017-3971 · Mozilla+5 · Firefox Esr+7

Nicolas Grégoire

·

Publicado

2017-02-05

·

Atualizado

2024-12-12

·

CVE-2017-5440

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 52.1 Firefox ESR versions prior to 52.1 Firefox ESR versions prior to 45.9 Firefox versions prior to 53
Description A use-after-free issue occurs during XSLT processing due to a failure to propagate error conditions, leading to objects being used after they no longer exist, resulting in a potentially exploitable crash. The vulnerability is related to the txExecutionState function and is associated with the use of memory after it has been freed during the processing of XSLT documents. This can allow a remote attacker to cause a denial of service.
Recommendations For Thunderbird versions prior to 52.1, update to version 52.1 or later. For Firefox ESR versions prior to 52.1, update to version 52.1 or later. For Firefox ESR versions prior to 45.9, update to version 45.9 or later. For Firefox versions prior to 53, update to version 53 or later.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1505
ALT-PU-2017-1506
ALT-PU-2017-1553
ALT-PU-2017-1577
ALT-PU-2017-1578
ALT-PU-2018-1854
BDU:2020-05746
CESA-2017_1104
CESA-2017_1106
CESA-2017_1201
CVE-2017-5440
DLA-906-1
DSA-3831-1
MGASA-2017-0118
MGASA-2017-0139
MGASA-2018-0018
OPENSUSE-SU-2017:1268-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2017:1104
RHSA-2017:1106
RHSA-2017:1201
RHSA-2017_1104
RHSA-2017_1106
RHSA-2017_1201
SUSE-SU-2017:1175-1
SUSE-SU-2017:1248-1
SUSE-SU-2017:1669-1
SUSE-SU-2017:2235-1
USN-3260-1
USN-3260-2
USN-3278-1

Produtos afetados

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Ubuntu