CVE-2017-5470
Summary
| CVE | CVE-2017-5470 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-11 21:29:00 UTC |
| Updated | 2018-08-03 14:16:00 UTC |
| Description | Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Mozilla Firefox Multiple Bugs Let Remote Users Spoof URLs, Obtain Potentially Sensitive Information, and Execute Arbitrary Code and Let Local Users Gain Elevated Privileges - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Security vulnerabilities fixed in Thunderbird 52.2 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Mozilla Firefox CVE-2017-5470 Multiple Unspecified Memory Corruption Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-3881-1 firefox-esr |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox ESR 52.2 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Bug List |
CONFIRM |
bugzilla.mozilla.org |
Issue Tracking, Vendor Advisory |
| Security vulnerabilities fixed in Firefox 54 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Debian -- Security Information -- DSA-3918-1 icedove |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378160 Virtuozzo Linux Security Update for firefox (VZLSA-2017:1440)
- 378205 Virtuozzo Linux Security Update for thunderbird (VZLSA-2017:1561)
- 710287 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 201802-03)