CVE-2017-5464
Last modified
CVE-2017-5464 is a vulnerability of currently unknown severity. During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.. EPSS estimates a 2.59% chance of exploitation in the next 30 days.
Description
During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 8.0 |
| Redhat | Enterprise Linux | 6.0 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.3 |
| Redhat | Enterprise Linux Server Aus | 7.4 |
| Redhat | Enterprise Linux Server Eus | 7.3 |
| Redhat | Enterprise Linux Server Eus | 7.4 |
| Redhat | Enterprise Linux Server Eus | 7.5 |
| Redhat | Enterprise Linux Workstation | 6.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Mozilla | Firefox | < 53.0 |
| Mozilla | Firefox | 52.0 |
| Mozilla | Thunderbird | < 52.1.0 |
References
- http://www.securityfocus.com/bid/97940Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038320Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1104Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1106Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1201Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1347075Issue Tracking, Vendor Advisory
- https://www.debian.org/security/2017/dsa-3831Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-10/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-11/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-12/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-13/Vendor Advisory
- http://www.securityfocus.com/bid/97940Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038320Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1104Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1106Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1201Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1347075Issue Tracking, Vendor Advisory
- https://www.debian.org/security/2017/dsa-3831Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-10/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-11/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-12/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2017-13/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5464?
How severe is CVE-2017-5464?
How do I fix CVE-2017-5464?
Are you affected by CVE-2017-5464?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
