CVE-2017-5404
published 2018-06-11CVE-2017-5404: A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results…
PriorityP260critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
17.48%
96.8th percentile
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | firefox | < firefox 52.0-1 (sid) | firefox 52.0-1 (sid) |
| debian | firefox-esr | < firefox 52.0-1 (sid) | firefox 52.0-1 (sid) |
| mozilla | firefox | < 52.0 | 52.0 |
| mozilla | firefox | < 45.8.0 | 45.8.0 |
| mozilla | firefox | >= 0 < 52.0+build2-0ubuntu0.14.04.1 | 52.0+build2-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 52.0.2+build1-0ubuntu0.14.04.1 | 52.0.2+build1-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 52.0+build2-0ubuntu0.16.04.1 | 52.0+build2-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 52.0.2+build1-0ubuntu0.16.04.1 | 52.0.2+build1-0ubuntu0.16.04.1 |
| mozilla | firefox | >= unspecified < 52 | 52 |
| mozilla | firefox_esr | >= unspecified < 45.8 | 45.8 |
| mozilla | thunderbird | < 45.8.0 | 45.8.0 |
| mozilla | thunderbird | >= 0 < 1:45.8.0+build1-0ubuntu0.14.04.1 | 1:45.8.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:45.8.0+build1-0ubuntu0.16.04.1 | 1:45.8.0+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= unspecified < 52 | 52 |
| mozilla | thunderbird | >= unspecified < 45.8 | 45.8 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit triggers use-after-free via Selection.modify('extend','forward','line') followed by appending a 'table' element and forcing garbage collection — monitor for this JS pattern in browser content ↗
- →Crash originates in nsRange::CloneRange() called from nsHTMLCopyEncoder::SetSelection() — look for UAF crash signatures in Firefox/Thunderbird involving nsRange and Selection manipulation ↗
- ·Affected versions are Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8; patched versions are not vulnerable ↗
- ·The PoC exploit requires domFuzzLite3 extension to be installed for the forceGC() call to succeed; without it the GC step fails gracefully ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox regression
vendor_ubuntu·2017-03-30·CVSS 9.8
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: USN-3216-1 introduced a regression in Firefox.
USN-3216-1 fixed vulnerabilities in Firefox. The update resulted in a
startup crash when Firefox is used with XRDP. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to bypass same origin restrictions, obtain
sensitive information, spoof the addressbar, spoof the print dialog,
cause a denial of service via application crash or hang, or execute
arbitrary code. (CVE-2017-5398, CVE-2017-5399, CVE-2017-5400,
CVE-2017-5401, CVE-2017-5402, CVE-2017-5403, CVE-2017-5404, CVE-2017-5405,
CVE-2017-5406, CVE-2017
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2017-03-24·CVSS 9.8
CVE-2017-5398 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to bypass same origin
restrictions, obtain sensitive information, cause a denial of service via
application crash or hang, or execute arbitrary code. (CVE-2017-5398,
CVE-2017-5400, CVE-2017-5401, CVE-2017-5402, CVE-2017-5404, CVE-2017-5405,
CVE-2017-5407, CVE-2017-5408, CVE-2017-5410)
Instructions: After a standard system update you need to restart Thunderbird to make
all the necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2017-03-07·CVSS 9.8
CVE-2017-5398 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to bypass same origin restrictions, obtain
sensitive information, spoof the addressbar, spoof the print dialog,
cause a denial of service via application crash or hang, or execute
arbitrary code. (CVE-2017-5398, CVE-2017-5399, CVE-2017-5400,
CVE-2017-5401, CVE-2017-5402, CVE-2017-5403, CVE-2017-5404, CVE-2017-5405,
CVE-2017-5406, CVE-2017-5407, CVE-2017-5408, CVE-2017-5410, CVE-2017-5412,
CVE-2017-5413, CVE-2017-5414, CVE-2017-5415, CVE-2017-5416, CVE-2017-5417,
CVE-2017-5418, CVE-2017-5419, CVE
Red Hat
Mozilla: Use-after-free working with ranges in selections (MFSA 2017-06)
vendor_redhat·2017-03-07·CVSS 9.8
CVE-2017-5404 [CRITICAL] Mozilla: Use-after-free working with ranges in selections (MFSA 2017-06)
Mozilla: Use-after-free working with ranges in selections (MFSA 2017-06)
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Debian
CVE-2017-5404: firefox - A use-after-free error can occur when manipulating ranges in selections with one...
vendor_debian·2017·CVSS 9.8
CVE-2017-5404 [CRITICAL] CVE-2017-5404: firefox - A use-after-free error can occur when manipulating ranges in selections with one...
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Scope: local
sid: resolved (fixed in 52.0-1)
GHSA
GHSA-2m8q-984r-f6q8: A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it
ghsa_unreviewed·2022-05-14
CVE-2017-5404 [CRITICAL] CWE-416 GHSA-2m8q-984r-f6q8: A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
OSV
CVE-2017-5404: A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it
osv·2018-06-11·CVSS 9.8
CVE-2017-5404 [CRITICAL] CVE-2017-5404: A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
OSV
firefox regression
osv·2017-03-30·CVSS 9.8
[CRITICAL] firefox regression
firefox regression
USN-3216-1 fixed vulnerabilities in Firefox. The update resulted in a
startup crash when Firefox is used with XRDP. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to bypass same origin restrictions, obtain
sensitive information, spoof the addressbar, spoof the print dialog,
cause a denial of service via application crash or hang, or execute
arbitrary code. (CVE-2017-5398, CVE-2017-5399, CVE-2017-5400,
CVE-2017-5401, CVE-2017-5402, CVE-2017-5403, CVE-2017-5404, CVE-2017-5405,
CVE-2017-5406, CVE-2017-5407, CVE-2017-5408, CVE-2017-5410, CVE-2017-5412,
CVE-2017-541
OSV
thunderbird vulnerabilities
osv·2017-03-24·CVSS 9.8
CVE-2017-5398 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to bypass same origin
restrictions, obtain sensitive information, cause a denial of service via
application crash or hang, or execute arbitrary code. (CVE-2017-5398,
CVE-2017-5400, CVE-2017-5401, CVE-2017-5402, CVE-2017-5404, CVE-2017-5405,
CVE-2017-5407, CVE-2017-5408, CVE-2017-5410)
OSV
firefox vulnerabilities
osv·2017-03-07·CVSS 9.8
CVE-2017-5398 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to bypass same origin restrictions, obtain
sensitive information, spoof the addressbar, spoof the print dialog,
cause a denial of service via application crash or hang, or execute
arbitrary code. (CVE-2017-5398, CVE-2017-5399, CVE-2017-5400,
CVE-2017-5401, CVE-2017-5402, CVE-2017-5403, CVE-2017-5404, CVE-2017-5405,
CVE-2017-5406, CVE-2017-5407, CVE-2017-5408, CVE-2017-5410, CVE-2017-5412,
CVE-2017-5413, CVE-2017-5414, CVE-2017-5415, CVE-2017-5416, CVE-2017-5417,
CVE-2017-5418, CVE-2017-5419, CVE-2017-5420, CVE-2017-5421, CVE-2017-5422,
CVE-2017-5426, CVE-2017-5427)
No detection rules found.
http://rhn.redhat.com/errata/RHSA-2017-0459.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0461.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0498.htmlhttp://www.securityfocus.com/bid/96664http://www.securitytracker.com/id/1037966https://bugzilla.mozilla.org/show_bug.cgi?id=1340138https://security.gentoo.org/glsa/201705-06https://security.gentoo.org/glsa/201705-07https://www.debian.org/security/2017/dsa-3805https://www.debian.org/security/2017/dsa-3832https://www.exploit-db.com/exploits/41660/https://www.mozilla.org/security/advisories/mfsa2017-05/https://www.mozilla.org/security/advisories/mfsa2017-06/https://www.mozilla.org/security/advisories/mfsa2017-07/https://www.mozilla.org/security/advisories/mfsa2017-09/http://rhn.redhat.com/errata/RHSA-2017-0459.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0461.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0498.htmlhttp://www.securityfocus.com/bid/96664http://www.securitytracker.com/id/1037966https://bugzilla.mozilla.org/show_bug.cgi?id=1340138https://security.gentoo.org/glsa/201705-06https://security.gentoo.org/glsa/201705-07https://www.debian.org/security/2017/dsa-3805https://www.debian.org/security/2017/dsa-3832https://www.exploit-db.com/exploits/41660/https://www.mozilla.org/security/advisories/mfsa2017-05/https://www.mozilla.org/security/advisories/mfsa2017-06/https://www.mozilla.org/security/advisories/mfsa2017-07/https://www.mozilla.org/security/advisories/mfsa2017-09/
2018-06-11
Published