CVE-2017-5378
Summary
| CVE | CVE-2017-5378 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-11 21:29:00 UTC |
| Updated | 2018-08-02 19:43:00 UTC |
| Description | Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, and also allows for data leakage of an object's content using these hash codes. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Mozilla Firefox Multiple Security Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| 1312001 - (CVE-2017-5378) ASLR leak and cross-frame oracle via pointer scrambling in Map/Set |
CONFIRM |
bugzilla.mozilla.org |
Exploit, Issue Tracking, Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| Mozilla Firefox Multiple Bugs Let Remote Users Bypass Security Restrictions, Spoof URLs, Obtain Potentially Sensitive Information, and Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Mozilla Firefox: Multiple vulnerabilities (GLSA 201702-22) — Gentoo Security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Security vulnerabilities fixed in Thunderbird 45.7 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Debian -- Security Information -- DSA-3832-1 icedove |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Debian -- Security Information -- DSA-3771-1 firefox-esr |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox 51 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| 1330769 - ASLR leak via pointer scrambling in ShapeTable |
CONFIRM |
bugzilla.mozilla.org |
Issue Tracking, Patch, Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| Mozilla Thunderbird: Multiple vulnerabilities (GLSA 201702-13) — Gentoo Security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox ESR 45.7 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378238 Virtuozzo Linux Security Update for firefox (VZLSA-2017:0190)
- 378298 Virtuozzo Linux Security Update for thunderbird (VZLSA-2017:0238)
- 710433 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 201702-13)
- 710488 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 201702-22)