CVE-2017-7772

Source
Severity High
Remote Yes
Type Arbitrary code execution
Description
A heap-buffer-overflow write has been found in the Graphite 2 library used in Firefox < 54.0 and Thunderbird < 52.2, in lz4::decompress.
Group Package Affected Fixed Severity Status Ticket
AVG-303 thunderbird 52.1.1-1 52.2.0-1 Critical Fixed
AVG-302 firefox 53.0.3-1 54.0-1 Critical Fixed
Date Advisory Group Package Severity Description
16 Jun 2017 ASA-201706-20 AVG-303 thunderbird Critical multiple issues
16 Jun 2017 ASA-201706-19 AVG-302 firefox Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2017-15/#CVE-2017-7778
https://bugzilla.mozilla.org/show_bug.cgi?id=1352745