CVE-2017-5428

An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.
References
Link Resource
https://www.mozilla.org/security/advisories/mfsa2017-08/ Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1348168 Exploit Issue Tracking Patch Vendor Advisory
http://www.securitytracker.com/id/1038060 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/96959 Third Party Advisory VDB Entry
http://rhn.redhat.com/errata/RHSA-2017-0558.html Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-06-11 21:29

Updated : 2018-08-09 15:27


NVD link : CVE-2017-5428

Mitre link : CVE-2017-5428


JSON object : View

Products Affected

redhat

  • enterprise_linux_server_eus
  • enterprise_linux
  • enterprise_linux_desktop
  • enterprise_linux_server
  • enterprise_linux_server_aus
  • enterprise_linux_workstation

mozilla

  • firefox_esr
  • firefox
CWE
CWE-190

Integer Overflow or Wraparound