First published: Tue Jan 24 2017(Updated: )
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 115.4.0esr-1 | |
Thunderbird | <45.7 | 45.7 |
Firefox | <51 | 51 |
Firefox ESR | <45.7 | 45.7 |
Firefox | <51.0 | |
Firefox ESR | <45.7.0 | |
Thunderbird | <45.7.0 | |
Debian Linux | =8.0 | |
Red Hat Enterprise Linux Desktop | =5.0 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =5.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Workstation | =5.0 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-5373 has a moderate severity level due to the potential for memory corruption vulnerabilities that could allow arbitrary code execution.
To fix CVE-2017-5373, update affected products to the latest versions: Firefox and Thunderbird version 45.7 or later, and Firefox ESR version 45.7 or later.
CVE-2017-5373 affects Firefox versions up to 51, Firefox ESR versions up to 45.7, and Thunderbird versions up to 45.7.
While there have been reports of memory safety bugs, no specific exploits for CVE-2017-5373 have been publicly disclosed.
Check if you are using affected versions of Firefox, Firefox ESR, or Thunderbird; if so, you are vulnerable to CVE-2017-5373.