First published: Tue Aug 08 2017(Updated: )
Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 118.0.2-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 | |
Thunderbird | <52.3 | 52.3 |
Debian | =8.0 | |
Debian | =9.0 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.4 | |
Red Hat Enterprise Linux Server | =7.5 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
Firefox | <55.0 | |
Firefox ESR | <52.3.0 | |
Thunderbird | <52.3.0 | |
Firefox | <55 | 55 |
Firefox ESR | <52.3 | 52.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7779 has been categorized with a severity that indicates potential for memory corruption which could be exploited to execute arbitrary code.
To address CVE-2017-7779, upgrade to Firefox version 55 or later, Firefox ESR version 52.3 or later, or Thunderbird version 52.3 or later.
CVE-2017-7779 affects Firefox versions below 55, Firefox ESR versions below 52.3, and Thunderbird versions below 52.3.
CVE-2017-7779 is associated with memory safety bugs leading to potential memory corruption.
Yes, there are patches available for CVE-2017-7779 in the form of software updates for the affected products.