CVE-2017-5411

A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while still in use in some circumstances, leading to a potentially exploitable crash. Note: This issue is in "libGLES", which is only in use on Windows. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:27

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/96692 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/96692 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1037966 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1037966 - Third Party Advisory, VDB Entry
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1325511 - Exploit, Issue Tracking, Vendor Advisory () https://bugzilla.mozilla.org/show_bug.cgi?id=1325511 - Exploit, Issue Tracking, Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2017-05/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2017-05/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2017-09/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2017-09/ - Vendor Advisory

Information

Published : 2018-06-11 21:29

Updated : 2024-11-21 03:27


NVD link : CVE-2017-5411

Mitre link : CVE-2017-5411

CVE.ORG link : CVE-2017-5411


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird

microsoft

  • windows
CWE
CWE-416

Use After Free