Описание
A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| firefox | fixed | 51.0-1 | package | |
| firefox-esr | fixed | 45.7.0esr-1 | package | |
| icedove | fixed | 1:45.7.1-1 | package |
Примечания
https://www.mozilla.org/en-US/security/advisories/mfsa2017-01/#CVE-2017-5396
https://www.mozilla.org/en-US/security/advisories/mfsa2017-02/#CVE-2017-5396
https://www.mozilla.org/en-US/security/advisories/mfsa2017-03/#CVE-2017-5396
EPSS
Связанные уязвимости
A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
EPSS