CVE-2017-5428 — Integer Overflow or Wraparound in Mozilla Firefox
Severity
9.8CRITICALNVD
EPSS
0.4%
top 41.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14
Description
An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages8 packages
Also affects: Enterprise Linux 7.0, 7.3, 7.4, 7.5
Patches
🔴Vulnerability Details
4GHSA▶
GHSA-3c9m-5j33-vjf4: An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest↗2022-05-14
CVEList▶
CVE-2017-5428: An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest↗2018-06-11
OSV▶
CVE-2017-5428: An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest↗2017-03-20