CVE-2017-5428Integer Overflow or Wraparound in Mozilla Firefox

Severity
9.8CRITICALNVD
EPSS
0.4%
top 41.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages8 packages

CVEListV5mozilla/firefoxunspecified52.0.1
NVDmozilla/firefox< 52.0.1
CVEListV5mozilla/firefox_esrunspecified52.0.1
NVDmozilla/firefox_esr< 52.0.1
Ubuntumozilla/firefox< 52.0.1+build2-0ubuntu0.14.04.1+1

Also affects: Enterprise Linux 7.0, 7.3, 7.4, 7.5

Patches

🔴Vulnerability Details

4
GHSA
GHSA-3c9m-5j33-vjf4: An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest2022-05-14
CVEList
CVE-2017-5428: An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest2018-06-11
OSV
firefox vulnerability2017-03-20
OSV
CVE-2017-5428: An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest2017-03-20

📋Vendor Advisories

3
Ubuntu
Firefox vulnerability2017-03-20
Red Hat
Mozilla: integer overflow in createImageBitmap() (MFSA 2017-08)2017-03-17
Debian
CVE-2017-5428: firefox - An integer overflow in "createImageBitmap()" was reported through the Pwn2Own co...2017

💬Community

1
Bugzilla
CVE-2017-5428 Mozilla: integer overflow in createImageBitmap() (MFSA 2017-08)2017-03-17
CVE-2017-5428 — Integer Overflow or Wraparound | cvebase