First published: Tue Jan 24 2017(Updated: )
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <45.7 | 45.7 |
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 115.4.0esr-1 | |
Mozilla Thunderbird | <45.7 | 45.7 |
Mozilla Firefox | <51 | 51 |
Mozilla Firefox | <51.0 | |
Mozilla Firefox ESR | <45.7.0 | |
Mozilla Thunderbird | <45.7.0 | |
Debian Debian Linux | =8.0 | |
redhat enterprise Linux desktop | =5.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux server | =5.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux workstation | =5.0 | |
redhat enterprise Linux workstation | =6.0 | |
redhat enterprise Linux workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-5373 has a moderate severity level due to the potential for memory corruption vulnerabilities that could allow arbitrary code execution.
To fix CVE-2017-5373, update affected products to the latest versions: Firefox and Thunderbird version 45.7 or later, and Firefox ESR version 45.7 or later.
CVE-2017-5373 affects Firefox versions up to 51, Firefox ESR versions up to 45.7, and Thunderbird versions up to 45.7.
While there have been reports of memory safety bugs, no specific exploits for CVE-2017-5373 have been publicly disclosed.
Check if you are using affected versions of Firefox, Firefox ESR, or Thunderbird; if so, you are vulnerable to CVE-2017-5373.