CVE-2017-5465: Critical severity Mozilla Thunderbird vulnerability
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Other sources
An out-of-bounds read while processing SVG content in <code>ConvolvePixel</code>. This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5465
Acknowledgements:
Name: the Mozilla project Upstream: Ivan Fratric (Google Project Zero)
— Red Hat
An out-of-bounds read while processing SVG content in ConvolvePixel. This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5433
- CVE-2017-5435
- CVE-2017-5436
- CVE-2017-5461
- CVE-2017-5459
- CVE-2017-5466
- CVE-2017-5434
- CVE-2017-5432
- CVE-2017-5460
- CVE-2017-5438
- CVE-2017-5439
- CVE-2017-5440
- CVE-2017-5441
- CVE-2017-5442
- CVE-2017-5464
- CVE-2017-5443
- CVE-2017-5444
- CVE-2017-5446
- CVE-2017-5447
- CVE-2017-5465
- CVE-2016-10196
- CVE-2017-5454
- CVE-2017-5469
- CVE-2017-5445
- CVE-2017-5449
- CVE-2017-5451
- CVE-2017-5462
- CVE-2017-5467
- CVE-2017-5430
- CVE-2017-5429
- CVE-2017-5448
- CVE-2017-5455
- CVE-2017-5456
- CVE-2017-5450
- CVE-2017-5463
- CVE-2017-5452
- CVE-2017-5453
- CVE-2017-5458
- CVE-2017-5468
Frequently Asked Questions
What is the severity of CVE-2017-5465?
CVE-2017-5465 is classified as a high severity vulnerability due to its potential for memory corruption and crashes.
What versions are affected by CVE-2017-5465?
CVE-2017-5465 affects Mozilla Thunderbird versions prior to 52.1 and Firefox ESR versions prior to 45.9 and 52.1.
How do I fix CVE-2017-5465?
To fix CVE-2017-5465, update Mozilla Thunderbird to version 52.1 or above, and update Firefox ESR to version 45.9 or above.
What types of applications are impacted by CVE-2017-5465?
CVE-2017-5465 impacts applications that process SVG content, specifically Mozilla Thunderbird and Firefox.
Can CVE-2017-5465 lead to remote code execution?
CVE-2017-5465 could potentially allow an attacker to exploit the vulnerability to execute code indirectly by accessing otherwise protected memory.