CVE-2017-5469: Buffer Overflow
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5469
Acknowledgements:
Name: the Mozilla project Upstream: Petr Cerny
Other sources
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 52.1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 53 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 45.9 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 52.1 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 137.0.1-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 128.9.0esr-1~deb11u1Fixed in 128.8.0esr-1~deb12u1Fixed in 128.9.0esr-1~deb12u1Fixed in 128.9.0esr-2 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 128.9.0esr-1~deb11u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 128.8.0esr-1~deb12u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 128.9.0esr-1~deb12u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 128.9.0esr-2
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5433
- CVE-2017-5435
- CVE-2017-5436
- CVE-2017-5461
- CVE-2017-5459
- CVE-2017-5466
- CVE-2017-5434
- CVE-2017-5432
- CVE-2017-5460
- CVE-2017-5438
- CVE-2017-5439
- CVE-2017-5440
- CVE-2017-5441
- CVE-2017-5442
- CVE-2017-5464
- CVE-2017-5443
- CVE-2017-5444
- CVE-2017-5446
- CVE-2017-5447
- CVE-2017-5465
- CVE-2016-10196
- CVE-2017-5454
- CVE-2017-5469
- CVE-2017-5445
- CVE-2017-5449
- CVE-2017-5451
- CVE-2017-5462
- CVE-2017-5467
- CVE-2017-5430
- CVE-2017-5429
- CVE-2017-5448
- CVE-2017-5455
- CVE-2017-5456
- CVE-2017-5450
- CVE-2017-5463
- CVE-2017-5452
- CVE-2017-5453
- CVE-2017-5458
- CVE-2017-5468
Frequently Asked Questions
What is the severity of CVE-2017-5469?
CVE-2017-5469 is considered a moderate severity vulnerability due to potential buffer overflow exploits.
How do I fix CVE-2017-5469?
To fix CVE-2017-5469, upgrade your Mozilla Thunderbird to version 52.1, or update your Firefox ESR to version 52.1 or 45.9, depending on your version.
Which versions of software are affected by CVE-2017-5469?
CVE-2017-5469 affects Mozilla Firefox up to version 53, Firefox ESR up to versions 52.1 and 45.9, and Mozilla Thunderbird up to version 52.1.
What kind of vulnerability is CVE-2017-5469?
CVE-2017-5469 is a buffer overflow vulnerability that could be exploited to crash or execute arbitrary code.
Is CVE-2017-5469 fixed in the latest updates?
Yes, CVE-2017-5469 has been fixed in the latest updates of affected software, including Mozilla Firefox and Thunderbird.