CVE-2017-5402: Use After Free
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Other sources
A use-after-free can occur when events are fired for a FontFace object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5400
- CVE-2017-5401
- CVE-2017-5402
- CVE-2017-5404
- CVE-2017-5407
- CVE-2017-5410
- CVE-2017-5408
- CVE-2017-5405
- CVE-2017-5398
- CVE-2017-5403
- CVE-2017-5406
- CVE-2017-5411
- CVE-2017-5412
- CVE-2017-5413
- CVE-2017-5414
- CVE-2017-5416
- CVE-2017-5425
- CVE-2017-5426
- CVE-2017-5418
- CVE-2017-5419
- CVE-2017-5421
- CVE-2017-5422
- CVE-2017-5399
- CVE-2017-5409
- CVE-2017-5415
- CVE-2017-5417
- CVE-2017-5427
- CVE-2017-5420
Frequently Asked Questions
What is the severity of CVE-2017-5402?
CVE-2017-5402 is classified as a potentially exploitable vulnerability, which could lead to application crashes.
How do I fix CVE-2017-5402?
To fix CVE-2017-5402, update affected products like Firefox to version 52 or later, and Thunderbird to version 45.8 or later.
Which software is affected by CVE-2017-5402?
CVE-2017-5402 affects Firefox versions prior to 52, Thunderbird versions prior to 52, and Firefox ESR versions prior to 45.8.
Can CVE-2017-5402 be exploited remotely?
While CVE-2017-5402 primarily leads to crashes, exploitation could potentially occur if an attacker can trigger a series of events related to a FontFace object.
Is there a workaround for CVE-2017-5402?
There are no known workarounds for CVE-2017-5402, so updating to the latest versions is strongly recommended.