CVE-2017-5378Sensitive Information Exposure in Mozilla Firefox

Severity
7.5HIGHNVD
OSV9.8
EPSS
1.7%
top 17.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, and also allows for data leakage of an object's content using these hash codes. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages10 packages

CVEListV5mozilla/firefoxunspecified51
NVDmozilla/firefox< 51.0+1
CVEListV5mozilla/firefox_esrunspecified45.7
Ubuntumozilla/firefox< 51.0.1+build2-0ubuntu0.14.04.1+3
CVEListV5mozilla/thunderbirdunspecified45.7

Also affects: Debian Linux 8.0, Enterprise Linux 5.0, 6.0, 7.0, 7.3, 7.4, 7.5

Patches

🔴Vulnerability Details

6
GHSA
GHSA-hx32-3942-m67q: Hashed codes of JavaScript objects are shared between pages2022-05-14
CVEList
CVE-2017-5378: Hashed codes of JavaScript objects are shared between pages2018-06-11
OSV
CVE-2017-5378: Hashed codes of JavaScript objects are shared between pages2018-06-11
OSV
firefox regression2017-02-06
OSV
thunderbird vulnerabilities2017-01-28

📋Vendor Advisories

5
Ubuntu
Firefox regression2017-02-06
Ubuntu
Thunderbird vulnerabilities2017-01-28
Ubuntu
Firefox vulnerabilities2017-01-27
Red Hat
Mozilla: Pointer and frame data leakage of Javascript objects (MFSA 2017-02)2017-01-24
Debian
CVE-2017-5378: firefox - Hashed codes of JavaScript objects are shared between pages. This allows for poi...2017

💬Community

1
Bugzilla
CVE-2017-5378 Mozilla: Pointer and frame data leakage of Javascript objects (MFSA 2017-02)2017-01-25
CVE-2017-5378 — Sensitive Information Exposure | cvebase