CVE-2017-5448: High severity Mozilla Firefox vulnerability
An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Other sources
An out-of-bounds write in <code>ClearKeyDecryptor</code> while decrypting some Clearkey-encrypted media content. This allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5448
Acknowledgements:
Name: the Mozilla project Upstream: Anonymous working with Trend Micro's Zero Day Initiative
— Red Hat
An out-of-bounds write in ClearKeyDecryptor while decrypting some Clearkey-encrypted media content. The ClearKeyDecryptor code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5433
- CVE-2017-5435
- CVE-2017-5436
- CVE-2017-5461
- CVE-2017-5459
- CVE-2017-5466
- CVE-2017-5434
- CVE-2017-5432
- CVE-2017-5460
- CVE-2017-5438
- CVE-2017-5439
- CVE-2017-5440
- CVE-2017-5441
- CVE-2017-5442
- CVE-2017-5464
- CVE-2017-5443
- CVE-2017-5444
- CVE-2017-5446
- CVE-2017-5447
- CVE-2017-5465
- CVE-2017-5448
- CVE-2016-10196
- CVE-2017-5454
- CVE-2017-5455
- CVE-2017-5456
- CVE-2017-5469
- CVE-2017-5445
- CVE-2017-5449
- CVE-2017-5450
- CVE-2017-5451
- CVE-2017-5462
- CVE-2017-5463
- CVE-2017-5467
- CVE-2017-5452
- CVE-2017-5453
- CVE-2017-5458
- CVE-2017-5468
- CVE-2017-5430
- CVE-2017-5429
Frequently Asked Questions
What is the severity of CVE-2017-5448?
CVE-2017-5448 is classified as a high-severity vulnerability due to the potential for an out-of-bounds write that could lead to arbitrary code execution if the sandbox is escaped.
How do I fix CVE-2017-5448?
To fix CVE-2017-5448, upgrade to Mozilla Firefox ESR version 45.9 or 52.1, or Mozilla Firefox version 53 and above.
What systems are vulnerable to CVE-2017-5448?
CVE-2017-5448 affects Mozilla Firefox and Firefox ESR versions prior to 45.9 and 52.1 respectively, along with various versions of Red Hat and Debian Linux.
When was CVE-2017-5448 disclosed?
CVE-2017-5448 was disclosed in March 2017 as part of Mozilla's security advisories.
What component is affected by CVE-2017-5448?
CVE-2017-5448 specifically affects the ClearKeyDecryptor component within the Gecko Media Plugin (GMP) sandbox.