First published: Thu Sep 28 2017(Updated: )
Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <56 | 56 |
Mozilla Firefox | <=55.0.3 | |
debian/firefox | 131.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-7813 is a vulnerability in the JavaScript parser of Mozilla Firefox and Ubuntu Firefox that can result in data leakage from memory.
CVE-2017-7813 has a severity rating of 8.2, which is considered high.
Mozilla Firefox versions up to and exclusive of 56.0.3, as well as Ubuntu Firefox versions 56.0+ on various Ubuntu releases, are affected by CVE-2017-7813.
To fix CVE-2017-7813, users should update their Mozilla Firefox or Ubuntu Firefox to version 56.0 or newer.
More information about CVE-2017-7813 can be found in the following references: [1] [2] [3]