CVE-2017-5472: Use After Free
A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CSS layout when attempting to use a node in the tree that no longer exists. This results in a potentially exploitable crash.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5472
- CVE-2017-7749
- CVE-2017-7750
- CVE-2017-7751
- CVE-2017-7755
- CVE-2017-7752
- CVE-2017-7754
- CVE-2017-7756
- CVE-2017-7757
- CVE-2017-7778
- CVE-2017-7758
- CVE-2017-7763
- CVE-2017-7764
- CVE-2017-7765
- CVE-2017-5470
- CVE-2017-7759
- CVE-2017-7760
- CVE-2017-7761
- CVE-2017-7762
- CVE-2017-7766
- CVE-2017-7767
- CVE-2017-7768
- CVE-2017-7770
- CVE-2017-5471
Frequently Asked Questions
What is the severity of CVE-2017-5472?
CVE-2017-5472 is classified as a high severity vulnerability due to its potential to cause crashes and possible exploitation.
How do I fix CVE-2017-5472?
To fix CVE-2017-5472, update Mozilla Firefox and Mozilla Thunderbird to the latest versions mentioned in the vulnerability's advisory.
Which software is affected by CVE-2017-5472?
CVE-2017-5472 affects various versions of Mozilla Firefox, Firefox ESR, and Thunderbird.
Can CVE-2017-5472 lead to remote code execution?
CVE-2017-5472 does not directly indicate a remote code execution risk, but it does present a potential security risk through crashes.
Is CVE-2017-5472 likely to be exploited in the wild?
There is potential for CVE-2017-5472 to be exploited in the wild, making immediate action to update affected software advisable.