CVE-2017-5445: Out-of-bounds Read
A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow the reading of uninitialized memory into the arrays affected. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Other sources
A vulnerability while parsing <code>application/http-index-format</code> format content where uninitialized values are used to create an array. This could allow the reading of uninitialized memory into the arrays affected.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5445
Acknowledgements:
Name: the Mozilla project Upstream: Chamal De Silva
— Red Hat
A vulnerability while parsing application/http-index-format format content where uninitialized values are used to create an array. This could allow the reading of uninitialized memory into the arrays affected.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5433
- CVE-2017-5435
- CVE-2017-5436
- CVE-2017-5461
- CVE-2017-5459
- CVE-2017-5466
- CVE-2017-5434
- CVE-2017-5432
- CVE-2017-5460
- CVE-2017-5438
- CVE-2017-5439
- CVE-2017-5440
- CVE-2017-5441
- CVE-2017-5442
- CVE-2017-5464
- CVE-2017-5443
- CVE-2017-5444
- CVE-2017-5446
- CVE-2017-5447
- CVE-2017-5465
- CVE-2016-10196
- CVE-2017-5454
- CVE-2017-5469
- CVE-2017-5445
- CVE-2017-5449
- CVE-2017-5451
- CVE-2017-5462
- CVE-2017-5467
- CVE-2017-5430
- CVE-2017-5429
- CVE-2017-5448
- CVE-2017-5455
- CVE-2017-5456
- CVE-2017-5450
- CVE-2017-5463
- CVE-2017-5452
- CVE-2017-5453
- CVE-2017-5458
- CVE-2017-5468
Frequently Asked Questions
What is the severity of CVE-2017-5445?
CVE-2017-5445 is classified as a moderative vulnerability that can lead to potential information disclosure.
How do I fix CVE-2017-5445?
To fix CVE-2017-5445, upgrade Thunderbird to version 52.1, Firefox ESR to version 52.1 or 45.9, or Firefox to version 53 or later.
What software is affected by CVE-2017-5445?
CVE-2017-5445 affects Mozilla Thunderbird versions prior to 52.1 and Mozilla Firefox versions prior to 53.
Can CVE-2017-5445 lead to memory-related issues?
Yes, CVE-2017-5445 can result in the reading of uninitialized memory into affected arrays.
Is there a known exploit for CVE-2017-5445?
As of now, there are no public exploits specifically targeting CVE-2017-5445.