First published: Tue Mar 07 2017(Updated: )
When adding a range to an object in the DOM, it is possible to use addRange to add the range to an incorrect root object. This triggers a use-after-free, resulting in a potentially exploitable crash.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <52 | 52 |
Thunderbird | <52 | 52 |
Thunderbird | <52.0 | |
Firefox | <52.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-5403 has a severity rating classified as medium due to the potential for crashes and possible exploitation.
To fix CVE-2017-5403, ensure that you update to the latest version of Mozilla Firefox or Mozilla Thunderbird beyond version 52.
CVE-2017-5403 affects Mozilla Firefox and Mozilla Thunderbird versions up to but not including version 52.
CVE-2017-5403 poses risks that could potentially be exploited remotely due to its nature of affecting web applications.
If CVE-2017-5403 is not addressed, users may experience crashes and may be vulnerable to potential exploit scenarios.