CVE-2017-7773: Buffer Overflow
A heap-based buffer overflow flaw related to "lz4::decompress" (src/Decompressor) has been reported in graphite2. A remote attacker could exploit this issue to cause a crash, or, possibly, execute arbitrary code.
Other sources
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7773?
CVE-2017-7773 is classified as a critical vulnerability due to the potential for remote code execution and system crashes.
How do I fix CVE-2017-7773?
To mitigate CVE-2017-7773, update Firefox to version 118.0.2-1 or Firefox ESR to any of the versions listed in the advisory.
Which software is affected by CVE-2017-7773?
CVE-2017-7773 affects specific versions of Firefox, Firefox ESR, and the Graphite2 library.
Can CVE-2017-7773 be exploited remotely?
Yes, CVE-2017-7773 can be exploited by remote attackers to cause crashes or execute arbitrary code.
What type of vulnerability is CVE-2017-7773?
CVE-2017-7773 is a heap-based buffer overflow vulnerability that affects the lz4::decompress function.