CVE-2017-5433
published 2018-06-11CVE-2017-5433: A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller…
PriorityP341critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.62%
88.2th percentile
A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | firefox | < firefox 52.0.1-1 (sid) | firefox 52.0.1-1 (sid) |
| debian | firefox-esr | < firefox 52.0.1-1 (sid) | firefox 52.0.1-1 (sid) |
| mozilla | firefox | < 45.9.0 | 45.9.0 |
| mozilla | firefox | < 53.0 | 53.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 53.0.2+build1-0ubuntu0.14.04.2 | 53.0.2+build1-0ubuntu0.14.04.2 |
| mozilla | firefox | >= 0 < 53.0+build6-0ubuntu0.14.04.1 | 53.0+build6-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 53.0.2+build1-0ubuntu0.16.04.2 | 53.0.2+build1-0ubuntu0.16.04.2 |
| mozilla | firefox | >= 0 < 53.0+build6-0ubuntu0.16.04.1 | 53.0+build6-0ubuntu0.16.04.1 |
| mozilla | firefox | >= unspecified < 53 | 53 |
| mozilla | firefox_esr | >= unspecified < 45.9 | 45.9 |
| mozilla | firefox_esr | >= unspecified < 52.1 | 52.1 |
| mozilla | thunderbird | < 52.1.0 | 52.1.0 |
| mozilla | thunderbird | >= 0 < 1:52.1.1+build1-0ubuntu0.14.04.1 | 1:52.1.1+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.1.1+build1-0ubuntu0.16.04.1 | 1:52.1.1+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= unspecified < 52.1 | 52.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3prh-hhv2-x5qr: A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation contr
ghsa_unreviewed·2022-05-14
CVE-2017-5433 [CRITICAL] CWE-416 GHSA-3prh-hhv2-x5qr: A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation contr
A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
OSV
CVE-2017-5433: A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation contr
osv·2018-06-11·CVSS 9.8
CVE-2017-5433 [CRITICAL] CVE-2017-5433: A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation contr
A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
OSV
thunderbird vulnerabilities
osv·2017-05-16·CVSS 9.8
CVE-2017-5429 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash, or execute arbitrary code. (CVE-2017-5429,
CVE-2017-5430, CVE-2017-5436, CVE-2017-5443, CVE-2017-5444, CVE-2017-5445,
CVE-2017-5446, CVE-2017-5447, CVE-2017-5461, CVE-2017-5467)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to spoof the addressbar
contents, conduct cross-site scripting (XSS) attacks, cause a denial of
service via application crash, or execute arbitrary code. (CV
OSV
firefox regression
osv·2017-05-11·CVSS 9.8
[CRITICAL] firefox regression
firefox regression
USN-3260-1 fixed vulnerabilities in Firefox. The update caused the
date picker panel and form validation errors to close immediately on
opening. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, obtain sensitive
information, spoof the addressbar contents or other UI elements, escape
the sandbox to read local files, conduct cross-site scripting (XSS)
attacks, cause a denial of service via application crash, or execute
arbitrary code. (CVE-2017-5429, CVE-2017-5430, CVE-2017-5432,
CVE-2017-5433, CVE-2017-5434, CVE-2017-5435, CVE-2017-543
OSV
firefox vulnerabilities
osv·2017-04-21·CVSS 9.8
CVE-2017-5429 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, obtain sensitive
information, spoof the addressbar contents or other UI elements, escape
the sandbox to read local files, conduct cross-site scripting (XSS)
attacks, cause a denial of service via application crash, or execute
arbitrary code. (CVE-2017-5429, CVE-2017-5430, CVE-2017-5432,
CVE-2017-5433, CVE-2017-5434, CVE-2017-5435, CVE-2017-5436, CVE-2017-5437,
CVE-2017-5438, CVE-2017-5439, CVE-2017-5440, CVE-2017-5441, CVE-2017-5442,
CVE-2017-5443, CVE-2017-5444, CVE-2017-5445, CVE-2017-5446, CVE-2017-5447,
CVE-2017-5448, CVE-2017-5449, CVE-2017-5451, CVE-2017-5453, CVE-2017-
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2017-05-16·CVSS 9.8
CVE-2017-5429 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash, or execute arbitrary code. (CVE-2017-5429,
CVE-2017-5430, CVE-2017-5436, CVE-2017-5443, CVE-2017-5444, CVE-2017-5445,
CVE-2017-5446, CVE-2017-5447, CVE-2017-5461, CVE-2017-5467)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to spoof the addressbar
contents, conduct cross-site scripting (XSS) attacks, cause a den
Ubuntu
Firefox regression
vendor_ubuntu·2017-05-11·CVSS 9.8
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: USN-3260-1 caused a regression in Firefox.
USN-3260-1 fixed vulnerabilities in Firefox. The update caused the
date picker panel and form validation errors to close immediately on
opening. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, obtain sensitive
information, spoof the addressbar contents or other UI elements, escape
the sandbox to read local files, conduct cross-site scripting (XSS)
attacks, cause a denial of service via application crash, or execute
arbitrary code. (CVE-2017-5429, CVE-2017-5430, CVE-2017-543
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2017-04-21·CVSS 9.8
CVE-2017-5429 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, obtain sensitive
information, spoof the addressbar contents or other UI elements, escape
the sandbox to read local files, conduct cross-site scripting (XSS)
attacks, cause a denial of service via application crash, or execute
arbitrary code. (CVE-2017-5429, CVE-2017-5430, CVE-2017-5432,
CVE-2017-5433, CVE-2017-5434, CVE-2017-5435, CVE-2017-5436, CVE-2017-5437,
CVE-2017-5438, CVE-2017-5439, CVE-2017-5440, CVE-2017-5441, CVE-2017-5442,
CVE-2017-5443, CVE-2017-5444, CV
Red Hat
Mozilla: Use-after-free in SMIL animation functions (MFSA 2017-11, MFSA 2017-12)
vendor_redhat·2017-04-19·CVSS 9.8
CVE-2017-5433 [CRITICAL] Mozilla: Use-after-free in SMIL animation functions (MFSA 2017-11, MFSA 2017-12)
Mozilla: Use-after-free in SMIL animation functions (MFSA 2017-11, MFSA 2017-12)
A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Package: firefox (Red Hat Enterprise Linux 5) - Will not fix
Package: thunderbird (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-5433: firefox - A use-after-free vulnerability in SMIL animation functions occurs when pointers ...
vendor_debian·2017·CVSS 9.8
CVE-2017-5433 [CRITICAL] CVE-2017-5433: firefox - A use-after-free vulnerability in SMIL animation functions occurs when pointers ...
A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
Use-after-free crash in SMILAnimationController::AddAnimationToCompositorTable
bugzilla·2023-04-19
Use-after-free crash in SMILAnimationController::AddAnimationToCompositorTable
Use-after-free crash in SMILAnimationController::AddAnimationToCompositorTable
Copying gsvelto's comments from bug 1828690:
We have a PHC crash under this signature: https://crash-stats.mozilla.org/report/index/936a8812-72e0-440d-acc7-6d0d70230406
The alloc and free stacks for that crash are the following:
Free stack:
```
#0 PLDHashTable::~PLDHashTable() (xul.dll)
#1 mozilla::SMILAnimationController::DoSample(bool) (xul.dll)
#2 mozilla::SMILTimeContainer::Sample() (xul.dll)
#3 nsRefreshDriver::Tick(mozilla::layers::BaseTransactionId, mozilla::TimeStamp, nsRefreshDriver::IsExtraTick) (xul.dll)
#4 mozilla::RefreshDriverTimer::TickRefreshDrivers(mozilla::layers::BaseTransactionId, mozilla::TimeStamp, nsTArray >&) (xul.dll)
#5 mozilla::RefreshDriverTimer::Tick(mozilla::layers::BaseTransact
Bugzilla
CVE-2017-5433 Mozilla: Use-after-free in SMIL animation functions (MFSA 2017-11, MFSA 2017-12)
bugzilla·2017-04-19·CVSS 9.8
CVE-2017-5433 [CRITICAL] CVE-2017-5433 Mozilla: Use-after-free in SMIL animation functions (MFSA 2017-11, MFSA 2017-12)
CVE-2017-5433 Mozilla: Use-after-free in SMIL animation functions (MFSA 2017-11, MFSA 2017-12)
A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5433
Acknowledgements:
Name: the Mozilla project
Upstream: Nils
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2017:1104 https://access.redhat.com/errata/RHSA-2017:1104
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1106 https://access.redhat.com/errata/RHSA-2
http://www.securityfocus.com/bid/97940http://www.securitytracker.com/id/1038320https://access.redhat.com/errata/RHSA-2017:1104https://access.redhat.com/errata/RHSA-2017:1106https://access.redhat.com/errata/RHSA-2017:1201https://bugzilla.mozilla.org/show_bug.cgi?id=1347168https://www.debian.org/security/2017/dsa-3831https://www.mozilla.org/security/advisories/mfsa2017-10/https://www.mozilla.org/security/advisories/mfsa2017-11/https://www.mozilla.org/security/advisories/mfsa2017-12/https://www.mozilla.org/security/advisories/mfsa2017-13/http://www.securityfocus.com/bid/97940http://www.securitytracker.com/id/1038320https://access.redhat.com/errata/RHSA-2017:1104https://access.redhat.com/errata/RHSA-2017:1106https://access.redhat.com/errata/RHSA-2017:1201https://bugzilla.mozilla.org/show_bug.cgi?id=1347168https://www.debian.org/security/2017/dsa-3831https://www.mozilla.org/security/advisories/mfsa2017-10/https://www.mozilla.org/security/advisories/mfsa2017-11/https://www.mozilla.org/security/advisories/mfsa2017-12/https://www.mozilla.org/security/advisories/mfsa2017-13/
2018-06-11
Published