CVE-2017-5398: Buffer Overflow
Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Other sources
Mozilla developers and community members Boris Zbarsky, Christian Holler, Honza Bambas, Jon Coppeard, Randell Jesup, André Bargull, Kan-Ru Chen, and Nathan Froyd reported memory safety bugs present in Firefox 51 and Firefox ESR 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
— Mozilla
Mozilla developers and community members Boris Zbarsky, Christian Holler, Honza Bambas, Jon Coppeard, Randell Jesup, André Bargull, Kan-Ru Chen, and Nathan Froyd reported memory safety bugs present in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5400
- CVE-2017-5401
- CVE-2017-5402
- CVE-2017-5404
- CVE-2017-5407
- CVE-2017-5410
- CVE-2017-5408
- CVE-2017-5405
- CVE-2017-5398
- CVE-2017-5403
- CVE-2017-5406
- CVE-2017-5411
- CVE-2017-5412
- CVE-2017-5413
- CVE-2017-5414
- CVE-2017-5416
- CVE-2017-5425
- CVE-2017-5426
- CVE-2017-5418
- CVE-2017-5419
- CVE-2017-5421
- CVE-2017-5422
- CVE-2017-5399
- CVE-2017-5409
- CVE-2017-5415
- CVE-2017-5417
- CVE-2017-5427
- CVE-2017-5420
Frequently Asked Questions
What is the severity of CVE-2017-5398?
CVE-2017-5398 is considered a high severity vulnerability due to its potential for memory corruption and arbitrary code execution.
How do I fix CVE-2017-5398?
To fix CVE-2017-5398, update Mozilla Thunderbird to version 45.8 or later, and upgrade Firefox and Firefox ESR to their respective patched versions.
What software is affected by CVE-2017-5398?
CVE-2017-5398 affects Mozilla Thunderbird versions prior to 45.8, and Firefox and Firefox ESR versions prior to 52.
Can CVE-2017-5398 be exploited?
Yes, CVE-2017-5398 could potentially be exploited to run arbitrary code if specific conditions are met.
What types of systems are impacted by CVE-2017-5398?
CVE-2017-5398 impacts systems running vulnerable versions of Mozilla Thunderbird, Firefox, and Firefox ESR across various platforms, including Debian and Red Hat.