PT-2017-3742 · Mozilla+5 · Firefox+8

Holger Fuhrmannek

+1

·

Published

2017-05-29

·

Updated

2024-06-15

·

CVE-2017-7778

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Graphite 2 versions prior to 1.3.10 Mozilla Firefox versions prior to 54 Mozilla Firefox ESR versions prior to 52.2 Thunderbird versions prior to 52.2
Description: The issue is related to the lz4::decompress function in the Graphite 2 library, which is used by Mozilla Firefox and Mozilla Firefox ESR. It involves an out-of-bounds buffer write in memory. Exploitation of this issue can allow a remote attacker to execute arbitrary code or cause a denial of service. Additionally, there are other security issues in the Graphite 2 library, including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory.
Recommendations: For Graphite 2 versions prior to 1.3.10, update to version 1.3.10 or later. For Mozilla Firefox versions prior to 54, update to version 54 or later. For Mozilla Firefox ESR versions prior to 52.2, update to version 52.2 or later. For Thunderbird versions prior to 52.2, update to version 52.2 or later.

Fix

Buffer Overflow

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1665
ALT-PU-2017-1770
ALT-PU-2017-1777
ALT-PU-2017-1886
ALT-PU-2018-1854
BDU:2019-00230
CESA-2017_1440
CESA-2017_1561
CESA-2017_1793
CVE-2017-7778
DLA-1007-1
DLA-1013-1
DLA-991-1
DSA-3881-1
DSA-3894-1
DSA-3918-1
MGASA-2017-0178
MGASA-2017-0180
MGASA-2017-0217
MGASA-2018-0018
OPENSUSE-SU-2017:1579-1
OPENSUSE-SU-2017_1620-1
OPENSUSE-SU-2024:10601-1
RHSA-2017:1440
RHSA-2017:1561
RHSA-2017:1793
RHSA-2017_1440
RHSA-2017_1561
RHSA-2017_1793
SUSE-SU-2017:1669-1
SUSE-SU-2017:2235-1
USN-3315-1
USN-3321-1
USN-3398-1

Affected Products

Alt Linux
Centos
Graphite 2
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Ubuntu