CVE-2017-7753: Critical severity thunderbird vulnerability
An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data.
Other sources
An out-of-bounds read when applying style rules to pseudo-elements like ::first-line using cached style data.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7753
Acknowledgements:
Name: the Mozilla project Upstream: SkyLined
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-7800
- CVE-2017-7801
- CVE-2017-7809
- CVE-2017-7784
- CVE-2017-7802
- CVE-2017-7785
- CVE-2017-7786
- CVE-2017-7753
- CVE-2017-7787
- CVE-2017-7807
- CVE-2017-7792
- CVE-2017-7804
- CVE-2017-7791
- CVE-2017-7782
- CVE-2017-7803
- CVE-2017-7779
- CVE-2017-7798
- CVE-2017-7806
- CVE-2017-7808
- CVE-2017-7781
- CVE-2017-7794
- CVE-2017-7799
- CVE-2017-7783
- CVE-2017-7788
- CVE-2017-7789
- CVE-2017-7790
- CVE-2017-7796
- CVE-2017-7797
- CVE-2017-7780
Frequently Asked Questions
What is the severity of CVE-2017-7753?
CVE-2017-7753 has a moderate severity rating due to the potential for out-of-bounds reads.
How do I fix CVE-2017-7753?
To fix CVE-2017-7753, update Thunderbird to version 52.3 or newer, or Firefox to versions specified in security advisories.
Which versions of Firefox are affected by CVE-2017-7753?
CVE-2017-7753 affects Firefox versions prior to 55.0.
Is Thunderbird vulnerable to CVE-2017-7753?
Yes, Thunderbird versions below 52.3 are vulnerable to CVE-2017-7753.
What are the recommended updates for Firefox ESR to mitigate CVE-2017-7753?
Firefox ESR versions prior to 52.3 are vulnerable; users should update to specified later versions to mitigate this vulnerability.