CVE-2017-5440: Use After Free
A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objects being used when they no longer exist. This results in a potentially exploitable crash.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5433
- CVE-2017-5435
- CVE-2017-5436
- CVE-2017-5461
- CVE-2017-5459
- CVE-2017-5466
- CVE-2017-5434
- CVE-2017-5432
- CVE-2017-5460
- CVE-2017-5438
- CVE-2017-5439
- CVE-2017-5440
- CVE-2017-5441
- CVE-2017-5442
- CVE-2017-5464
- CVE-2017-5443
- CVE-2017-5444
- CVE-2017-5446
- CVE-2017-5447
- CVE-2017-5465
- CVE-2016-10196
- CVE-2017-5454
- CVE-2017-5469
- CVE-2017-5445
- CVE-2017-5449
- CVE-2017-5451
- CVE-2017-5462
- CVE-2017-5467
- CVE-2017-5430
- CVE-2017-5429
- CVE-2017-5448
- CVE-2017-5455
- CVE-2017-5456
- CVE-2017-5450
- CVE-2017-5463
- CVE-2017-5452
- CVE-2017-5453
- CVE-2017-5458
- CVE-2017-5468
Frequently Asked Questions
What is the severity of CVE-2017-5440?
CVE-2017-5440 is classified as a medium severity vulnerability that can lead to potentially exploitable crashes.
How do I fix CVE-2017-5440?
To fix CVE-2017-5440, update your software to the latest versions including Firefox 53 or later, Firefox ESR 52.1 or later, or Thunderbird 52.1 or later.
Which software is affected by CVE-2017-5440?
CVE-2017-5440 affects Mozilla Firefox, Firefox ESR, and Thunderbird versions prior to their respective fixed releases.
What type of vulnerability is CVE-2017-5440?
CVE-2017-5440 is a use-after-free vulnerability that occurs during XSLT processing.
Can CVE-2017-5440 be exploited remotely?
Yes, CVE-2017-5440 could potentially be exploited remotely, as it allows unintended access to memory after it has been freed.