Vulnerability BDU:2021-00029: Information

Description

Уязвимость аудиокодека Opus браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании

Severity: CRITICAL (9.1) Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Published: May 29, 2017
Modified: May 29, 2017
Error type identifier: CWE-125

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus54.0.1-alt1126.0.1-alt1ALT-PU-2017-1886-1185325Fixed
firefoxp1054.0.1-alt1118.0.2-alt0.p10.1ALT-PU-2017-1886-1185325Fixed
firefoxp954.0.1-alt1105.0.1-alt0.c9.1ALT-PU-2017-1886-1185325Fixed
firefoxp854.0.1-alt0.M80P.168.0.1-alt0.M80P.1ALT-PU-2017-1981-1185512Fixed
firefoxc10f154.0.1-alt1112.0.2-alt0.p10.1ALT-PU-2017-1886-1185325Fixed
firefoxc9f254.0.1-alt1105.0.1-alt0.c9.1ALT-PU-2017-1886-1185325Fixed
firefoxc752.5.3-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2018-1225-1200642Fixed
firefoxp1154.0.1-alt1126.0.1-alt1ALT-PU-2017-1886-1185325Fixed
firefox-esrsisyphus52.2.0-alt1115.11.0-alt1ALT-PU-2017-1770-1184555Fixed
firefox-esrp1052.2.0-alt1115.11.0-alt1ALT-PU-2017-1770-1184555Fixed
firefox-esrp952.2.0-alt1102.11.0-alt0.c9.1ALT-PU-2017-1770-1184555Fixed
firefox-esrp852.3.0-alt0.M80P.168.4.1-alt0.M80P.1ALT-PU-2017-2230-1188380Fixed
firefox-esrc10f152.2.0-alt1115.9.1-alt0.c10.1ALT-PU-2017-1770-1184555Fixed
firefox-esrc9f252.2.0-alt1102.12.0-alt0.c9.1ALT-PU-2017-1770-1184555Fixed
firefox-esrp1152.2.0-alt1115.11.0-alt1ALT-PU-2017-1770-1184555Fixed
thunderbirdsisyphus52.2.0-alt1115.9.0-alt1ALT-PU-2017-1777-1184645Fixed
thunderbirdp1052.2.0-alt1115.9.0-alt1ALT-PU-2017-1777-1184645Fixed
thunderbirdp952.2.0-alt1102.11.0-alt0.c9.1ALT-PU-2017-1777-1184645Fixed
thunderbirdp852.3.0-alt0.M80P.160.8.0-alt0.M80P.1ALT-PU-2017-2238-1188382Fixed
thunderbirdc10f152.2.0-alt1115.9.0-alt0.c10.1ALT-PU-2017-1777-1184645Fixed
thunderbirdc9f252.2.0-alt1102.11.0-alt0.c9.1ALT-PU-2017-1777-1184645Fixed
thunderbirdc760.8.0-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2019-2345-1234994Fixed
thunderbirdp1152.2.0-alt1115.9.0-alt1ALT-PU-2017-1777-1184645Fixed

References to Advisories, Solutions, and Tools

Vulnerability Status
Подтверждена производителем
Presence of an exploit
Существует в открытом доступе
Fix status
Уязвимость устранена
Software Type
Операционная система, Прикладное ПО информационных систем
Solution
Использование рекомендаций:
Для продуктов Mozilla:
https://www.mozilla.org/security/advisories/mfsa2017-15/
https://www.mozilla.org/security/advisories/mfsa2017-16/
https://www.mozilla.org/security/advisories/mfsa2017-17/

Для Debian:
https://www.debian.org/security/2017/dsa-3881	 
https://www.debian.org/security/2017/dsa-3918

Для продуктов Red Hat:
https://access.redhat.com/security/cve/cve-2017-7758

Для продуктов Novell Inc.:
https://www.suse.com/security/cve/CVE-2017-7758/

Для Astra Linux:
https://wiki.astralinux.ru/pages/viewpage.action?pageId=1212483
https://wiki.astralinux.ru/astra-linux-se15-bulletin-20201201SE15

Для Альт Линукс:
https://cve.basealt.ru/

Для Ubuntu:
https://ubuntu.com/security/notices/USN-3315-1?_ga=2.253574793.1874363206.1609607440-1543702552.1605094901
https://ubuntu.com/security/notices/USN-3321-1?_ga=2.253574793.1874363206.1609607440-1543702552.1605094901
Sources
https://nvd.nist.gov/vuln/detail/CVE-2017-7758
https://security-tracker.debian.org/tracker/CVE-2017-7758
https://bugzilla.mozilla.org/show_bug.cgi?id=1368490
https://www.mozilla.org/security/advisories/mfsa2017-15/
https://www.mozilla.org/security/advisories/mfsa2017-16/
https://www.mozilla.org/security/advisories/mfsa2017-17/
https://www.debian.org/security/2017/dsa-3881	 
https://www.debian.org/security/2017/dsa-3918
https://access.redhat.com/security/cve/cve-2017-7758
https://www.suse.com/security/cve/CVE-2017-7758/
https://wiki.astralinux.ru/pages/viewpage.action?pageId=1212483
https://wiki.astralinux.ru/astra-linux-se15-bulletin-20201201SE15
https://cve.basealt.ru/
https://ubuntu.com/security/notices/USN-3315-1?_ga=2.253574793.1874363206.1609607440-1543702552.1605094901
https://ubuntu.com/security/notices/USN-3321-1?_ga=2.253574793.1874363206.1609607440-1543702552.1605094901
Other system identifiers