CVE-2017-7819: Use After Free
Published Sep 28, 2017
·Updated
A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from memory. This results in a potentially exploitable crash.
Affected Software
21 affected componentsFixes available
debian/firefox
131.0.2-2
debian/firefox-esr
115.14.0esr-1~deb11u1128.3.1esr-1~deb11u1115.14.0esr-1~deb12u1128.3.1esr-1~deb12u1128.3.0esr-2128.3.1esr-2
debian/thunderbird
1:115.12.0-1~deb11u11:115.16.0esr-1~deb11u11:115.12.0-1~deb12u11:115.16.0esr-1~deb12u11:128.2.0esr-11:128.3.0esr-1
Mozilla Thunderbird<52.4
52.4
Mozilla Firefox<56
56
Mozilla Firefox ESR<52.4
52.4
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Mozilla Firefox<56.0
Mozilla Firefox ESR<52.4.0
Mozilla Thunderbird<52.4.0
Mozilla Firefox<52.4.0
Remediation
Patch Available
Event History
Sep 28, 2017
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Red Hat·04:27 AM
DescriptionSeverityAffected Software
Jun 11, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:40 PM
Description
Sep 20, 2024
Data Sourced
via Ubuntu·01:52 AM
RemedyDescriptionSeverityAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2017-7819?
The severity of CVE-2017-7819 is critical with a CVSS v3.0 score of 9.8.
2
Which software is affected by CVE-2017-7819?
CVE-2017-7819 affects Firefox versions before 56, Firefox ESR versions before 52.4, and Thunderbird versions before 52.4.
3
How can I fix the vulnerability in Firefox?
To fix the vulnerability in Firefox, update to version 56 or later.
4
How can I fix the vulnerability in Firefox ESR?
To fix the vulnerability in Firefox ESR, update to version 52.4 or later.
5
How can I fix the vulnerability in Thunderbird?
To fix the vulnerability in Thunderbird, update to version 52.4 or later.