CVE-2017-5405DEPRECATED: Use of Uninitialized Resource in Mozilla Firefox

Severity
5.3MEDIUMNVD
OSV9.8
EPSS
2.4%
top 15.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 13

Description

Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages10 packages

CVEListV5mozilla/firefoxunspecified52
NVDmozilla/firefox< 52.0+1
CVEListV5mozilla/firefox_esrunspecified45.8
CVEListV5mozilla/thunderbirdunspecified52+1
NVDmozilla/thunderbird< 45.8.0

Also affects: Debian Linux 8.0, Enterprise Linux 5.0, 6.0, 7.0, 7.3, 7.4, 7.5

🔴Vulnerability Details

6
GHSA
GHSA-f5h5-w6rr-6gwm: Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations2022-05-13
OSV
CVE-2017-5405: Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations2018-06-11
CVEList
CVE-2017-5405: Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations2018-06-11
OSV
firefox regression2017-03-30
OSV
thunderbird vulnerabilities2017-03-24

📋Vendor Advisories

5
Ubuntu
Firefox regression2017-03-30
Ubuntu
Thunderbird vulnerabilities2017-03-24
Ubuntu
Firefox vulnerabilities2017-03-07
Red Hat
Mozilla: FTP response codes can cause use of uninitialized values for ports (MFSA 2017-06)2017-03-07
Debian
CVE-2017-5405: firefox - Certain response codes in FTP connections can result in the use of uninitialized...2017

💬Community

2
Bugzilla
CVE-2017-15135 389-ds-base: Authentication bypass due to lack of size check in slapi_ct_memcmp function in ch_malloc.c2017-12-13
Bugzilla
CVE-2017-5405 Mozilla: FTP response codes can cause use of uninitialized values for ports (MFSA 2017-06)2017-03-07
CVE-2017-5405 — Mozilla Firefox vulnerability | cvebase