CVE-2017-5373: Buffer Overflow
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Other sources
Mozilla developers and community members Christian Holler, Gary Kwong, André Bargull, Jan de Mooij, Tom Schuster, and Oriol reported memory safety bugs present in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
Mozilla developers and community members Christian Holler, Gary Kwong, André Bargull, Jan de Mooij, Tom Schuster, and Oriol reported memory safety bugs present in Thunderbird 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5375
- CVE-2017-5376
- CVE-2017-5378
- CVE-2017-5380
- CVE-2017-5390
- CVE-2017-5396
- CVE-2017-5383
- CVE-2017-5373
- CVE-2017-5377
- CVE-2017-5379
- CVE-2017-5389
- CVE-2017-5381
- CVE-2017-5382
- CVE-2017-5384
- CVE-2017-5385
- CVE-2017-5386
- CVE-2017-5394
- CVE-2017-5391
- CVE-2017-5392
- CVE-2017-5393
- CVE-2017-5395
- CVE-2017-5387
- CVE-2017-5388
- CVE-2017-5374
Frequently Asked Questions
What is the severity of CVE-2017-5373?
CVE-2017-5373 has a moderate severity level due to the potential for memory corruption vulnerabilities that could allow arbitrary code execution.
How do I fix CVE-2017-5373?
To fix CVE-2017-5373, update affected products to the latest versions: Firefox and Thunderbird version 45.7 or later, and Firefox ESR version 45.7 or later.
Which applications are affected by CVE-2017-5373?
CVE-2017-5373 affects Firefox versions up to 51, Firefox ESR versions up to 45.7, and Thunderbird versions up to 45.7.
Are there known exploits for CVE-2017-5373?
While there have been reports of memory safety bugs, no specific exploits for CVE-2017-5373 have been publicly disclosed.
How can I determine if my system is vulnerable to CVE-2017-5373?
Check if you are using affected versions of Firefox, Firefox ESR, or Thunderbird; if so, you are vulnerable to CVE-2017-5373.