CVE-2017-7752 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Arbitrary code execution |
Description | A use-after-free has been found in Firefox < 54.0 and Thunderbird < 52.2, during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash but would require specific user interaction to trigger. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-303 | thunderbird | 52.1.1-1 | 52.2.0-1 | Critical | Fixed | |
AVG-302 | firefox | 53.0.3-1 | 54.0-1 | Critical | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
16 Jun 2017 | ASA-201706-20 | AVG-303 | thunderbird | Critical | multiple issues |
16 Jun 2017 | ASA-201706-19 | AVG-302 | firefox | Critical | multiple issues |
References |
---|
https://www.mozilla.org/en-US/security/advisories/mfsa2017-15/#CVE-2017-7752 https://bugzilla.mozilla.org/show_bug.cgi?id=1359547 |