CVE-2017-7800: Use After Free
A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash.
Other sources
A use-after-free vulnerability in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7800
Acknowledgements:
Name: the Mozilla project Upstream: Looben Yang
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-7800
- CVE-2017-7801
- CVE-2017-7809
- CVE-2017-7784
- CVE-2017-7802
- CVE-2017-7785
- CVE-2017-7786
- CVE-2017-7753
- CVE-2017-7787
- CVE-2017-7807
- CVE-2017-7792
- CVE-2017-7804
- CVE-2017-7791
- CVE-2017-7782
- CVE-2017-7803
- CVE-2017-7779
- CVE-2017-7798
- CVE-2017-7806
- CVE-2017-7808
- CVE-2017-7781
- CVE-2017-7794
- CVE-2017-7799
- CVE-2017-7783
- CVE-2017-7788
- CVE-2017-7789
- CVE-2017-7790
- CVE-2017-7796
- CVE-2017-7797
- CVE-2017-7780
Frequently Asked Questions
What is the severity of CVE-2017-7800?
CVE-2017-7800 has a moderate severity level due to the potential for crashes and exploitation.
How do I fix CVE-2017-7800?
To fix CVE-2017-7800, update your affected software to the latest versions provided by Mozilla.
What software is affected by CVE-2017-7800?
CVE-2017-7800 affects multiple versions of Firefox, Firefox ESR, and Thunderbird running on various Linux distributions.
Is CVE-2017-7800 a critical vulnerability?
CVE-2017-7800 is not classified as critical, but it can lead to potential denial of service issues.
What could happen if CVE-2017-7800 is exploited?
Exploiting CVE-2017-7800 could result in crashes of the affected applications, impacting user session stability.