CVE-2017-5447: Use After Free
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5433
- CVE-2017-5435
- CVE-2017-5436
- CVE-2017-5461
- CVE-2017-5459
- CVE-2017-5466
- CVE-2017-5434
- CVE-2017-5432
- CVE-2017-5460
- CVE-2017-5438
- CVE-2017-5439
- CVE-2017-5440
- CVE-2017-5441
- CVE-2017-5442
- CVE-2017-5464
- CVE-2017-5443
- CVE-2017-5444
- CVE-2017-5446
- CVE-2017-5447
- CVE-2017-5465
- CVE-2016-10196
- CVE-2017-5454
- CVE-2017-5469
- CVE-2017-5445
- CVE-2017-5449
- CVE-2017-5451
- CVE-2017-5462
- CVE-2017-5467
- CVE-2017-5430
- CVE-2017-5429
- CVE-2017-5448
- CVE-2017-5455
- CVE-2017-5456
- CVE-2017-5450
- CVE-2017-5463
- CVE-2017-5452
- CVE-2017-5453
- CVE-2017-5458
- CVE-2017-5468
Frequently Asked Questions
What is the severity of CVE-2017-5447?
CVE-2017-5447 has a moderate severity rating due to the potential for memory disclosure and application crashes.
How do I fix CVE-2017-5447?
To remediate CVE-2017-5447, users should update to the latest versions of affected software, specifically Mozilla Thunderbird version 52.1 or higher, and Firefox ESR versions 52.1 or higher.
Which software is affected by CVE-2017-5447?
CVE-2017-5447 affects Mozilla Thunderbird, Mozilla Firefox, and various versions of Firefox ESR prior to specified patches.
What are the consequences of CVE-2017-5447?
Exploiting CVE-2017-5447 can lead to a crash of the affected application and potential exposure of sensitive memory content.
Is CVE-2017-5447 actively exploited in the wild?
As of the latest information, there have been no reported active exploits for CVE-2017-5447, but users should apply updates as a precaution.