CVE-2017-5444: Buffer Overflow
A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This allows for an out-of-bounds read of data from memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Other sources
A buffer overflow vulnerability while parsing <code>application/http-index-format</code> format content when the header contains improperly formatted data. This allows for an out-of-bounds read of data from memory.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5444
Acknowledgements:
Name: the Mozilla project Upstream: Chamal De Silva
— Red Hat
A buffer overflow vulnerability while parsing application/http-index-format format content when the header contains improperly formatted data. This allows for an out-of-bounds read of data from memory.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5433
- CVE-2017-5435
- CVE-2017-5436
- CVE-2017-5461
- CVE-2017-5459
- CVE-2017-5466
- CVE-2017-5434
- CVE-2017-5432
- CVE-2017-5460
- CVE-2017-5438
- CVE-2017-5439
- CVE-2017-5440
- CVE-2017-5441
- CVE-2017-5442
- CVE-2017-5464
- CVE-2017-5443
- CVE-2017-5444
- CVE-2017-5446
- CVE-2017-5447
- CVE-2017-5465
- CVE-2016-10196
- CVE-2017-5454
- CVE-2017-5469
- CVE-2017-5445
- CVE-2017-5449
- CVE-2017-5451
- CVE-2017-5462
- CVE-2017-5467
- CVE-2017-5430
- CVE-2017-5429
- CVE-2017-5448
- CVE-2017-5455
- CVE-2017-5456
- CVE-2017-5450
- CVE-2017-5463
- CVE-2017-5452
- CVE-2017-5453
- CVE-2017-5458
- CVE-2017-5468
Frequently Asked Questions
What is the severity of CVE-2017-5444?
CVE-2017-5444 has a medium severity level due to its potential to cause buffer overflows and memory corruption.
How do I fix CVE-2017-5444?
To fix CVE-2017-5444, update Thunderbird to version 52.1 or later, and Firefox ESR to version 52.1 or later.
Which software is affected by CVE-2017-5444?
CVE-2017-5444 affects versions of Thunderbird below 52.1 and Firefox ESR versions below 52.1.
What type of vulnerability is CVE-2017-5444?
CVE-2017-5444 is a buffer overflow vulnerability that occurs while parsing improperly formatted HTTP index format content.
Can CVE-2017-5444 lead to further attacks?
Yes, CVE-2017-5444 could potentially allow attackers to execute arbitrary code or trigger other security issues due to memory corruption.