PT-2017-3740 · Mozilla+5 · Firefox Esr+7
Holger Fuhrmannek
+1
·
Published
2017-05-29
·
Updated
2019-04-15
·
CVE-2017-7772
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Graphite 2 versions prior to 54
Mozilla Firefox versions prior to 54
Mozilla Firefox ESR versions prior to 54
Description:
The issue is caused by a heap-based buffer overflow in the lz4::decompress function of the Graphite 2 library. This can be exploited by a remote attacker to cause a denial of service or execute arbitrary code.
Recommendations:
For Graphite 2 versions prior to 54, update to version 54 or later to resolve the issue.
For Mozilla Firefox versions prior to 54, update to version 54 or later to resolve the issue.
For Mozilla Firefox ESR versions prior to 54, update to version 54 or later to resolve the issue.
Exploit
Fix
Heap Based Buffer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Graphite 2
Firefox
Firefox Esr
Red Hat
Suse
Ubuntu