Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption, which leads to potentially exploitable crashes. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/95763 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1037693 | Third Party Advisory VDB Entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=1293709 | Issue Tracking Vendor Advisory |
https://www.mozilla.org/security/advisories/mfsa2017-01/ | Vendor Advisory |
http://www.securityfocus.com/bid/95763 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1037693 | Third Party Advisory VDB Entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=1293709 | Issue Tracking Vendor Advisory |
https://www.mozilla.org/security/advisories/mfsa2017-01/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 03:27
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/95763 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1037693 - Third Party Advisory, VDB Entry | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1293709 - Issue Tracking, Vendor Advisory | |
References | () https://www.mozilla.org/security/advisories/mfsa2017-01/ - Vendor Advisory |
Information
Published : 2018-06-11 21:29
Updated : 2024-11-21 03:27
NVD link : CVE-2017-5392
Mitre link : CVE-2017-5392
CVE.ORG link : CVE-2017-5392
JSON object : View
Products Affected
mozilla
- firefox
- android
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer