CVE-2017-7828: Use After Free
A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been freed while still in use. This results in a potentially exploitable crash during these operations. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
Other sources
A use-after-free vulnerability can occur when flushing and resizing layout because the PressShell object has been freed while still in use. This results in a potentially exploitable crash during these operations.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2017-7828?
CVE-2017-7828 is a use-after-free vulnerability that can occur when flushing and resizing layout in Firefox, Firefox ESR, and Thunderbird.
What is the severity of CVE-2017-7828?
CVE-2017-7828 has a severity level of critical (9 out of 10).
How does CVE-2017-7828 affect Firefox?
CVE-2017-7828 affects Firefox versions before 57.
How does CVE-2017-7828 affect Firefox ESR?
CVE-2017-7828 affects Firefox ESR versions before 52.5.
How does CVE-2017-7828 affect Thunderbird?
CVE-2017-7828 affects Thunderbird versions before 52.5.
How do I fix CVE-2017-7828?
To fix CVE-2017-7828, update Firefox to version 57 or later, Firefox ESR to version 52.5 or later, and Thunderbird to version 52.5 or later.