cbcvebase.
CVE-2017-5448
published 2018-06-11

CVE-2017-5448: An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media…

high8.6CVSS 3.0
AVNACLPRNUINSUCLILAH
An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianfirefox< firefox 52.0.1-1 (sid)firefox 52.0.1-1 (sid)
debianfirefox-esr< firefox 52.0.1-1 (sid)firefox 52.0.1-1 (sid)
mozillafirefox< 45.9.045.9.0
mozillafirefox< 53.053.0
mozillafirefox>= 0 < 53.0.2+build1-0ubuntu0.14.04.253.0.2+build1-0ubuntu0.14.04.2
mozillafirefox>= 0 < 53.0+build6-0ubuntu0.14.04.153.0+build6-0ubuntu0.14.04.1
mozillafirefox>= 0 < 53.0.2+build1-0ubuntu0.16.04.253.0.2+build1-0ubuntu0.16.04.2
mozillafirefox>= 0 < 53.0+build6-0ubuntu0.16.04.153.0+build6-0ubuntu0.16.04.1
mozillafirefox>= 52.0 < 52.1.052.1.0
mozillafirefox>= unspecified < 5353
mozillafirefox_esr>= unspecified < 45.945.9
mozillafirefox_esr>= unspecified < 52.152.1
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
osv9.8CRITICAL