CVE-2017-7802: Use After Free
A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack of strong references, a potentially exploitable crash may occur when the freed elements are accessed.
Other sources
A use-after-free vulnerability when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack of strong references, a potentially exploitable crash may occur when the freed elements are accessed.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7802
Acknowledgements:
Name: the Mozilla project Upstream: Nils
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-7800
- CVE-2017-7801
- CVE-2017-7809
- CVE-2017-7784
- CVE-2017-7802
- CVE-2017-7785
- CVE-2017-7786
- CVE-2017-7753
- CVE-2017-7787
- CVE-2017-7807
- CVE-2017-7792
- CVE-2017-7804
- CVE-2017-7791
- CVE-2017-7782
- CVE-2017-7803
- CVE-2017-7779
- CVE-2017-7798
- CVE-2017-7806
- CVE-2017-7808
- CVE-2017-7781
- CVE-2017-7794
- CVE-2017-7799
- CVE-2017-7783
- CVE-2017-7788
- CVE-2017-7789
- CVE-2017-7790
- CVE-2017-7796
- CVE-2017-7797
- CVE-2017-7780
Frequently Asked Questions
What is the severity of CVE-2017-7802?
CVE-2017-7802 has a medium severity rating due to the potential for a crash when accessing freed elements.
How do I fix CVE-2017-7802?
To fix CVE-2017-7802, you should update Firefox to version 118.0.2-1 or later, and for Firefox ESR, update to specific versions listed in the vulnerability details.
Which software is affected by CVE-2017-7802?
CVE-2017-7802 affects Firefox, Firefox ESR, and Thunderbird across several specific versions.
Can CVE-2017-7802 be exploited remotely?
Yes, CVE-2017-7802 could potentially be exploited remotely if an attacker can manipulate the DOM during the resize event.
Is CVE-2017-7802 specific to a certain operating system?
CVE-2017-7802 is not specific to any one operating system but affects software running on various versions of Debian and Red Hat Enterprise Linux.