PT-2018-8245 · Mozilla+2 · Firefox+2

Honza Bambas

·

Published

2017-02-02

·

Updated

2024-12-12

·

CVE-2017-5392

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Firefox versions prior to 51
Description: The issue arises from weak proxy objects having weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption. This leads to potentially exploitable crashes. The issue only affects Firefox for Android, with other operating systems not being affected.
Recommendations: For versions prior to 51, update to version 51 or later to resolve the issue.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1138
CVE-2017-5392
OPENSUSE-SU-2017_0358-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1

Affected Products

Alt Linux
Firefox
Suse