CVE-2017-7754: High severity thunderbird vulnerability
An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Other sources
An out-of-bounds read in WebGL with a maliciously crafted ImageInfo object during WebGL operations.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5472
- CVE-2017-7749
- CVE-2017-7750
- CVE-2017-7751
- CVE-2017-7755
- CVE-2017-7752
- CVE-2017-7754
- CVE-2017-7756
- CVE-2017-7757
- CVE-2017-7778
- CVE-2017-7758
- CVE-2017-7763
- CVE-2017-7764
- CVE-2017-7765
- CVE-2017-5470
- CVE-2017-7759
- CVE-2017-7760
- CVE-2017-7761
- CVE-2017-7762
- CVE-2017-7766
- CVE-2017-7767
- CVE-2017-7768
- CVE-2017-7770
- CVE-2017-5471
Frequently Asked Questions
What is the severity of CVE-2017-7754?
CVE-2017-7754 is classified as a high-severity vulnerability due to the potential for exploitation through out-of-bounds reads.
How do I fix CVE-2017-7754?
To fix CVE-2017-7754, update to Firefox version 54, Firefox ESR version 52.2, or Thunderbird version 52.2.
Which versions of affected software are vulnerable to CVE-2017-7754?
Firefox versions below 54, Firefox ESR versions below 52.2, and Thunderbird versions below 52.2 are vulnerable to CVE-2017-7754.
What type of vulnerability is CVE-2017-7754?
CVE-2017-7754 is an out-of-bounds read vulnerability that occurs during WebGL operations.
Who is affected by CVE-2017-7754?
Users of Firefox, Firefox ESR, and Thunderbird versions lower than the specified ones are primarily affected by CVE-2017-7754.