Vulnerability Description
An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.3 |
| Redhat | Enterprise Linux Server Eus | 7.3 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Mozilla | Firefox | < 52.0.1 |
| Mozilla | Firefox Esr | < 52.0.1 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2017-0558.htmlThird Party Advisory
- http://www.securityfocus.com/bid/96959Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038060Third Party AdvisoryVDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1348168ExploitIssue TrackingPatch
- https://www.mozilla.org/security/advisories/mfsa2017-08/Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0558.htmlThird Party Advisory
- http://www.securityfocus.com/bid/96959Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038060Third Party AdvisoryVDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1348168ExploitIssue TrackingPatch
- https://www.mozilla.org/security/advisories/mfsa2017-08/Vendor Advisory
FAQ
What is CVE-2017-5428?
CVE-2017-5428 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function...
How severe is CVE-2017-5428?
CVE-2017-5428 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-5428?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Server Aus, Redhat Enterprise Linux Server Eus.