A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Thunderbird < 52.5.2, Firefox ESR < 52.5.2, and Firefox < 57.0.2.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefox-esr | Jan 26, 2018 | Dec 20, 2017 |
| Freebsd | — | Upgrade thunderbirdUpgrade linux-thunderbird | Dec 25, 2017 | Dec 25, 2017 |
| Mfsa2017 28 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 52.5.2 | Dec 8, 2017 | Dec 7, 2017 |
| Mfsa2017 29 | — | Upgrade to Mozilla Firefox version 57.0.2Upgrade to the latest version of Mozilla Firefox | Dec 8, 2017 | Dec 7, 2017 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 52.5.2Upgrade to the latest version of Mozilla Thunderbird | Jan 2, 2018 | Dec 22, 2017 |
| Oracle Solaris | — | Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 52.6.0-0.175.3.29.0.4.0 on Solaris 11.3Upgrade mail/thunderbird to version 52.6.0-0.175.3.29.0.4.0 on Solaris 11.3 | Feb 6, 2018 | Feb 6, 2018 |
| Suse | — | Upgrade MozillaThunderbird-develUpgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbird-translations-commonUpgrade MozillaThunderbird | May 20, 2018 | Dec 22, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub