5
CVSSv2

CVE-2017-7805

Published: 11/06/2018 Updated: 17/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 56.0

mozilla firefox esr 52.4.0

mozilla thunderbird 52.4.0

debian debian linux 7.0

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Synopsis Important: nss security update Type/Severity Security Advisory: Important Topic An update for nss is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Sy ...
Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service For the oldstable distribution (jessie), these problems have been fixed in version 1:5240-1~deb8u1 For the stable distribution (stretch), these problems have been fixed in version 1:5240-1~deb9u1 We recommend that y ...
Martin Thomson discovered that nss, the Mozilla Network Security Service library, is prone to a use-after-free vulnerability in the TLS 12 implementation when handshake hashes are generated A remote attacker can take advantage of this flaw to cause an application using the nss library to crash, resulting in a denial of service, or potentially to ...
NSS could be made to crash or run programs if it received specially crafted network traffic ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Several security issues were fixed in Thunderbird ...
USN-3435-1 caused a regression in Firefox ...
Potential use-after-free in TLS 12 server when verifying client authentication:A use-after-free flaw was found in the TLS 12 implementation in the NSS library when client authentication was used A malicious client could use this flaw to cause an application compiled against NSS to crash or, potentially, execute arbitrary code with the permission ...
A security issue has been found in Thunderbird &lt; 524 During TLS 12 exchanges, handshake hashes are generated which point to a message buffer This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer This leaves a pointer ...
Mozilla Foundation Security Advisory 2017-21 Security vulnerabilities fixed in Firefox 56 Announced September 28, 2017 Impact critical Products Firefox Fixed in Firefox 56 ...
Mozilla Foundation Security Advisory 2017-22 Security vulnerabilities fixed in Firefox ESR 524 Announced September 28, 2017 Impact critical Products Firefox ESR Fixed in Firefox ESR 524 ...
Mozilla Foundation Security Advisory 2017-23 Security vulnerabilities fixed in Thunderbird 524 Announced October 9, 2017 Impact critical Products Thunderbird Fixed in Thunderbird 524 ...