CVE-2017-7828

Source
Severity Critical
Remote Yes
Type Arbitrary code execution
Description
A use-after-free vulnerability can occur in Firefox before 57.0 and Thunderbird before 52.5 when flushing and resizing layout because the PressShell object has been freed while still in use. This results in a potentially exploitable crash during these operations.
Group Package Affected Fixed Severity Status Ticket
AVG-530 thunderbird 52.4.0-2 52.5.0-1 Critical Fixed
AVG-494 firefox 56.0.2-1 57.0-1 Critical Fixed
Date Advisory Group Package Severity Description
30 Nov 2017 ASA-201711-43 AVG-530 thunderbird Critical multiple issues
15 Nov 2017 ASA-201711-23 AVG-494 firefox Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2017-24/#CVE-2017-7828
https://bugzilla.mozilla.org/show_bug.cgi?id=1406750
https://bugzilla.mozilla.org/show_bug.cgi?id=1412252