Related Vulnerabilities: CVE-2017-5400  

JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks.

Severity Critical

Remote Yes

Type Arbitrary code execution

Description

JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks.

AVG-194 firefox 51.0.1-1 52.0-1 Critical Fixed

AVG-193 thunderbird 45.7.1-3 45.8.0-1 Critical Fixed

10 Mar 2017 ASA-201703-3 AVG-194 firefox Critical multiple issues

10 Mar 2017 ASA-201703-2 AVG-193 thunderbird Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2017-07/#CVE-2017-5400
https://bugzilla.mozilla.org/show_bug.cgi?id=1334933