CVE-2017-5398
Summary
| CVE | CVE-2017-5398 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-11 21:29:00 UTC |
| Updated | 2018-08-01 12:05:00 UTC |
| Description | Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Mozilla Thunderbird: Multiple vulnerabilities (GLSA 201705-07) — Gentoo Security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| Security vulnerabilities fixed in Thunderbird 45.8 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Mozilla Firefox: Multiple vulnerabilities (GLSA 201705-06) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Mozilla Firefox Multiple Bugs Let Remote Users Bypass Security Restrictions, Spoof URLs, Obtain Potentially Sensitive Information, Deny Service, and Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Mozilla Firefox and Thunderbird CVE-2017-5398 Multiple Unspecified Memory-Corruption Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-3832-1 icedove |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Security vulnerabilities fixed in - Thunderbird 52 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Bug List |
CONFIRM |
bugzilla.mozilla.org |
Issue Tracking, Permissions Required, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox ESR 45.8 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-3805-1 firefox-esr |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox 52 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378239 Virtuozzo Linux Security Update for thunderbird (VZLSA-2017:0498)
- 378313 Virtuozzo Linux Security Update for firefox (VZLSA-2017:0459)
- 378319 Virtuozzo Linux Security Update for firefox (VZLSA-2017:0461)
- 710423 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 201705-06)
- 710543 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 201705-07)