CVE-2017-7824

A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
References
Link Resource
http://www.securityfocus.com/bid/101053 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1039465 Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2017:2831 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2885 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1398381 Issue Tracking
https://lists.debian.org/debian-lts-announce/2017/11/msg00000.html Mailing List Third Party Advisory
https://security.gentoo.org/glsa/201803-14 Third Party Advisory
https://www.debian.org/security/2017/dsa-3987 Third Party Advisory
https://www.debian.org/security/2017/dsa-4014 Third Party Advisory
https://www.mozilla.org/security/advisories/mfsa2017-21/ Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2017-22/ Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2017-23/ Vendor Advisory
http://www.securityfocus.com/bid/101053 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1039465 Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2017:2831 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2885 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1398381 Issue Tracking
https://lists.debian.org/debian-lts-announce/2017/11/msg00000.html Mailing List Third Party Advisory
https://security.gentoo.org/glsa/201803-14 Third Party Advisory
https://www.debian.org/security/2017/dsa-3987 Third Party Advisory
https://www.debian.org/security/2017/dsa-4014 Third Party Advisory
https://www.mozilla.org/security/advisories/mfsa2017-21/ Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2017-22/ Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2017-23/ Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_aus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:7.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-06-11 21:29

Updated : 2024-11-21 03:32


NVD link : CVE-2017-7824

Mitre link : CVE-2017-7824

CVE.ORG link : CVE-2017-7824


JSON object : View

Products Affected

redhat

  • enterprise_linux_workstation
  • enterprise_linux_desktop
  • enterprise_linux_eus
  • enterprise_linux_aus
  • enterprise_linux_server

debian

  • debian_linux

mozilla

  • thunderbird
  • firefox_esr
  • firefox
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer