First published: Tue Jan 24 2017(Updated: )
A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of time due to a lack of rate limiting being applied on e10s systems, allowing for a denial of service attack. This vulnerability affects Firefox < 51.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <51 | 51 |
Firefox | <51.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-5388 has a severity rating of high due to its potential to cause a denial of service attack.
To fix CVE-2017-5388, upgrade Firefox to version 51 or newer.
CVE-2017-5388 affects Firefox versions prior to 51, particularly on e10s systems.
CVE-2017-5388 allows for a denial of service attack by exploiting a lack of rate limiting.
There is no specific workaround for CVE-2017-5388 other than upgrading the affected software.