CVE-2017-7801: Use After Free
A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Other sources
A use-after-free vulnerability can occur while re-computing layout for a marquee element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash.
A use-after-free vulnerability while re-computing layout for a marquee element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7801
Acknowledgements:
Name: the Mozilla project Upstream: Nils
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-7800
- CVE-2017-7801
- CVE-2017-7809
- CVE-2017-7784
- CVE-2017-7802
- CVE-2017-7785
- CVE-2017-7786
- CVE-2017-7753
- CVE-2017-7787
- CVE-2017-7807
- CVE-2017-7792
- CVE-2017-7804
- CVE-2017-7791
- CVE-2017-7782
- CVE-2017-7803
- CVE-2017-7779
- CVE-2017-7798
- CVE-2017-7806
- CVE-2017-7808
- CVE-2017-7781
- CVE-2017-7794
- CVE-2017-7799
- CVE-2017-7783
- CVE-2017-7788
- CVE-2017-7789
- CVE-2017-7790
- CVE-2017-7796
- CVE-2017-7797
- CVE-2017-7780
Frequently Asked Questions
What is the severity of CVE-2017-7801?
CVE-2017-7801 is classified as a high severity use-after-free vulnerability that could result in a potentially exploitable crash.
How do I fix CVE-2017-7801?
To fix CVE-2017-7801, update your Mozilla Thunderbird and Firefox applications to version 52.3 or later.
Which versions of Thunderbird are affected by CVE-2017-7801?
CVE-2017-7801 affects Thunderbird versions prior to 52.3.
Is CVE-2017-7801 present in all Firefox versions?
CVE-2017-7801 impacts Firefox versions prior to 55, including Firefox ESR versions before 52.3.
What platforms are affected by CVE-2017-7801?
CVE-2017-7801 affects multiple platforms running outdated versions of Thunderbird and Firefox, particularly on Debian and Red Hat Enterprise Linux.