cbcvebase.
CVE-2017-5447
published 2018-06-11

CVE-2017-5447: An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to…

PriorityP261critical9.1CVSS 3.0
AVNACLPRNUINSUCHINAH
EXPLOIT
EPSS
17.53%
96.8th percentile
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianfirefox< firefox 52.0.1-1 (sid)firefox 52.0.1-1 (sid)
debianfirefox-esr< firefox 52.0.1-1 (sid)firefox 52.0.1-1 (sid)
mozillafirefox< 45.9.045.9.0
mozillafirefox< 53.053.0
mozillafirefox
mozillafirefox>= 0 < 53.0.2+build1-0ubuntu0.14.04.253.0.2+build1-0ubuntu0.14.04.2
mozillafirefox>= 0 < 53.0+build6-0ubuntu0.14.04.153.0+build6-0ubuntu0.14.04.1
mozillafirefox>= 0 < 53.0.2+build1-0ubuntu0.16.04.253.0.2+build1-0ubuntu0.16.04.2
mozillafirefox>= 0 < 53.0+build6-0ubuntu0.16.04.153.0+build6-0ubuntu0.16.04.1
mozillafirefox>= unspecified < 5353
mozillafirefox_esr>= unspecified < 45.945.9
mozillafirefox_esr>= unspecified < 52.152.1
mozillathunderbird< 52.1.052.1.0
mozillathunderbird>= 0 < 1:52.1.1+build1-0ubuntu0.14.04.11:52.1.1+build1-0ubuntu0.14.04.1
mozillathunderbird>= 0 < 1:52.1.1+build1-0ubuntu0.16.04.11:52.1.1+build1-0ubuntu0.16.04.1
mozillathunderbird>= unspecified < 52.152.1
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5447
  • Exploit PoC triggers via CSS float layout combined with canvas.toBlob() callback loop and flex-direction style property toggling, causing out-of-bounds read in glyph width processing during text layout reflow
  • Crash originates in gfxTextRun allocation path; monitor for out-of-bounds reads in AllocateStorageForTextRun / gfxFontGroup::MakeTextRun during text layout reflow
  • Exploit HTML uses CSS classes with float:left, white-space:pre-line, border-bottom-style:solid, and large font-size (7ex) to trigger the vulnerable text layout code path
  • Crash occurs 0 bytes past end of a 204-byte heap region allocated for text run storage; look for heap-buffer-overflow/ASAN reports in Firefox/Thunderbird gfx subsystem
  • ·Vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53; versions at or above these thresholds are not affected
  • ·Red Hat Enterprise Linux 5 packages for both firefox and thunderbird are marked 'Will not fix' — detection on RHEL5 systems should be prioritized as patching is unavailable

CVSS provenance

nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.