First published: Tue Jun 13 2017(Updated: )
An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 | |
Thunderbird | <52.2 | 52.2 |
Debian | =8.0 | |
Debian | =9.0 | |
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.3 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.3 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.5 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
Thunderbird | <52.2.0 | |
Firefox | <54.0 | |
Firefox ESR | <52.2.0 | |
Firefox | <54 | 54 |
Firefox ESR | <52.2 | 52.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7754 is classified as a high-severity vulnerability due to the potential for exploitation through out-of-bounds reads.
To fix CVE-2017-7754, update to Firefox version 54, Firefox ESR version 52.2, or Thunderbird version 52.2.
Firefox versions below 54, Firefox ESR versions below 52.2, and Thunderbird versions below 52.2 are vulnerable to CVE-2017-7754.
CVE-2017-7754 is an out-of-bounds read vulnerability that occurs during WebGL operations.
Users of Firefox, Firefox ESR, and Thunderbird versions lower than the specified ones are primarily affected by CVE-2017-7754.