Vulnerability BDU:2018-00157: Information

Description

Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с использованием памяти после освобождения, позволяющая нарушителю вызвать отказ в обслуживании

Severity: HIGH (7.5) Vector: AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: July 12, 2017
Modified: July 12, 2017
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus56.0-alt1126.0.1-alt1ALT-PU-2017-2437-1190760Fixed
firefoxp1056.0-alt1118.0.2-alt0.p10.1ALT-PU-2017-2437-1190760Fixed
firefoxp956.0-alt1105.0.1-alt0.c9.1ALT-PU-2017-2437-1190760Fixed
firefoxp856.0-alt0.M80P.168.0.1-alt0.M80P.1ALT-PU-2017-2453-1190905Fixed
firefoxc10f156.0-alt1112.0.2-alt0.p10.1ALT-PU-2017-2437-1190760Fixed
firefoxc9f256.0-alt1105.0.1-alt0.c9.1ALT-PU-2017-2437-1190760Fixed
firefoxc752.5.3-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2018-1225-1200642Fixed
firefoxp1156.0-alt1126.0.1-alt1ALT-PU-2017-2437-1190760Fixed
firefox-esrsisyphus52.4.0-alt1115.11.0-alt1ALT-PU-2017-2358-1189704Fixed
firefox-esrp1052.4.0-alt1115.11.0-alt1ALT-PU-2017-2358-1189704Fixed
firefox-esrp952.4.0-alt1102.11.0-alt0.c9.1ALT-PU-2017-2358-1189704Fixed
firefox-esrp852.4.0-alt0.M80P.168.4.1-alt0.M80P.1ALT-PU-2017-2359-1189718Fixed
firefox-esrc10f152.4.0-alt1115.9.1-alt0.c10.1ALT-PU-2017-2358-1189704Fixed
firefox-esrc9f252.4.0-alt1102.12.0-alt0.c9.1ALT-PU-2017-2358-1189704Fixed
firefox-esrp1152.4.0-alt1115.11.0-alt1ALT-PU-2017-2358-1189704Fixed
thunderbirdsisyphus52.4.0-alt1115.9.0-alt1ALT-PU-2017-2390-1190451Fixed
thunderbirdp1052.4.0-alt1115.9.0-alt1ALT-PU-2017-2390-1190451Fixed
thunderbirdp952.4.0-alt1102.11.0-alt0.c9.1ALT-PU-2017-2390-1190451Fixed
thunderbirdp852.4.0-alt0.M80P.160.8.0-alt0.M80P.1ALT-PU-2017-2391-1190492Fixed
thunderbirdc10f152.4.0-alt1115.9.0-alt0.c10.1ALT-PU-2017-2390-1190451Fixed
thunderbirdc9f252.4.0-alt1102.11.0-alt0.c9.1ALT-PU-2017-2390-1190451Fixed
thunderbirdc760.8.0-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2019-2345-1234994Fixed
thunderbirdp1152.4.0-alt1115.9.0-alt1ALT-PU-2017-2390-1190451Fixed

References to Advisories, Solutions, and Tools

Vulnerability Status
Подтверждена производителем
Presence of an exploit
Существует в открытом доступе
Fix status
Уязвимость устранена
Software Type
Операционная система, Прикладное ПО информационных систем
Solution
Использование рекомендаций:
Для продуктов Mozilla:
https://www.mozilla.org/security/advisories/mfsa2017-21/	
https://www.mozilla.org/security/advisories/mfsa2017-22/
https://www.mozilla.org/security/advisories/mfsa2017-23/

Для Astra Linux:
https://wiki.astralinux.ru/pages/viewpage.action?pageId=1212483

Для Альт Линукс:
https://cve.basealt.ru/

Для Debian:
https://lists.debian.org/debian-lts-announce/2017/11/msg00000.html	
https://www.debian.org/security/2017/dsa-3987	
https://www.debian.org/security/2017/dsa-4014

Для Ubuntu:
https://usn.ubuntu.com/usn/usn-3435-1
https://usn.ubuntu.com/usn/usn-3436-1

Для продуктов Red Hat:
https://access.redhat.com/security/cve/cve-2017-7819

Для продуктов Novell Inc.:
https://www.suse.com/security/cve/CVE-2017-7819/
Sources
https://nvd.nist.gov/vuln/detail/CVE-2017-7819
https://security-tracker.debian.org/tracker/CVE-2017-7819
https://bugzilla.mozilla.org/show_bug.cgi?id=1380292
https://www.mozilla.org/security/advisories/mfsa2017-21/	
https://www.mozilla.org/security/advisories/mfsa2017-22/
https://www.mozilla.org/security/advisories/mfsa2017-23/
https://wiki.astralinux.ru/pages/viewpage.action?pageId=1212483
https://cve.basealt.ru/
https://lists.debian.org/debian-lts-announce/2017/11/msg00000.html	
https://www.debian.org/security/2017/dsa-3987	
https://www.debian.org/security/2017/dsa-4014
https://usn.ubuntu.com/usn/usn-3435-1
https://usn.ubuntu.com/usn/usn-3436-1
https://access.redhat.com/security/cve/cve-2017-7819
https://www.suse.com/security/cve/CVE-2017-7819/
Other system identifiers