CVE-2017-5376: Use After Free
Published Jan 24, 2017
·Updated
Use-after-free while manipulating XSL in XSLT documents
Affected Software
27 affected componentsFixes available
debian/firefox
118.0.2-1
debian/firefox-esr
91.12.0esr-1~deb10u1115.3.1esr-1~deb10u1102.15.0esr-1~deb11u1115.3.1esr-1~deb11u1102.15.1esr-1~deb12u1115.3.0esr-1~deb12u1115.3.0esr-1115.4.0esr-1
Mozilla Thunderbird<45.7
45.7
Mozilla Firefox<51
51
Mozilla Firefox ESR<45.7
45.7
Debian Debian Linux=9.0
redhat Enterprise Linux=5.0
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux Desktop=5.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=5.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Eus=7.3
redhat Enterprise Linux Server Eus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Workstation=5.0
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
Mozilla Thunderbird<45.7.0
Mozilla Firefox<51.0
Mozilla Firefox ESR<45.7.0
Mozilla Firefox<45.7.0
Event History
Jan 24, 2017
CVE Published
via Mozilla·12:00 AM
Jun 11, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5375
- CVE-2017-5376
- CVE-2017-5378
- CVE-2017-5380
- CVE-2017-5390
- CVE-2017-5396
- CVE-2017-5383
- CVE-2017-5373
- CVE-2017-5377
- CVE-2017-5379
- CVE-2017-5389
- CVE-2017-5381
- CVE-2017-5382
- CVE-2017-5384
- CVE-2017-5385
- CVE-2017-5386
- CVE-2017-5394
- CVE-2017-5391
- CVE-2017-5392
- CVE-2017-5393
- CVE-2017-5395
- CVE-2017-5387
- CVE-2017-5388
- CVE-2017-5374
Frequently Asked Questions
1
What is the severity of CVE-2017-5376?
CVE-2017-5376 has a moderate severity rating due to the potential for exploitation through affected software.
2
How do I fix CVE-2017-5376?
To fix CVE-2017-5376, update Mozilla Thunderbird or Firefox to version 45.7 or higher.
3
Which versions of Thunderbird are affected by CVE-2017-5376?
Thunderbird versions below 45.7 are affected by CVE-2017-5376.
4
Which versions of Firefox are affected by CVE-2017-5376?
CVE-2017-5376 affects Firefox versions below 51 and Firefox ESR versions below 45.7.
5
What types of attacks can exploit CVE-2017-5376?
CVE-2017-5376 can be exploited through crafted XSLT documents leading to potential execution of arbitrary code.