Vulnerability BDU:2021-00034: Information

Description

Уязвимость загрузчика фреймов браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании

Severity: CRITICAL (9.8) Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: June 14, 2017
Modified: June 14, 2017
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus54.0.1-alt1126.0.1-alt1ALT-PU-2017-1886-1185325Fixed
firefoxp1054.0.1-alt1118.0.2-alt0.p10.1ALT-PU-2017-1886-1185325Fixed
firefoxp954.0.1-alt1105.0.1-alt0.c9.1ALT-PU-2017-1886-1185325Fixed
firefoxp854.0.1-alt0.M80P.168.0.1-alt0.M80P.1ALT-PU-2017-1981-1185512Fixed
firefoxc10f154.0.1-alt1112.0.2-alt0.p10.1ALT-PU-2017-1886-1185325Fixed
firefoxc9f254.0.1-alt1105.0.1-alt0.c9.1ALT-PU-2017-1886-1185325Fixed
firefoxc752.5.3-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2018-1225-1200642Fixed
firefoxp1154.0.1-alt1126.0.1-alt1ALT-PU-2017-1886-1185325Fixed
firefox-esrsisyphus52.2.0-alt1115.11.0-alt1ALT-PU-2017-1770-1184555Fixed
firefox-esrp1052.2.0-alt1115.11.0-alt1ALT-PU-2017-1770-1184555Fixed
firefox-esrp952.2.0-alt1102.11.0-alt0.c9.1ALT-PU-2017-1770-1184555Fixed
firefox-esrp852.3.0-alt0.M80P.168.4.1-alt0.M80P.1ALT-PU-2017-2230-1188380Fixed
firefox-esrc10f152.2.0-alt1115.9.1-alt0.c10.1ALT-PU-2017-1770-1184555Fixed
firefox-esrc9f252.2.0-alt1102.12.0-alt0.c9.1ALT-PU-2017-1770-1184555Fixed
firefox-esrp1152.2.0-alt1115.11.0-alt1ALT-PU-2017-1770-1184555Fixed
thunderbirdsisyphus52.2.0-alt1115.9.0-alt1ALT-PU-2017-1777-1184645Fixed
thunderbirdp1052.2.0-alt1115.9.0-alt1ALT-PU-2017-1777-1184645Fixed
thunderbirdp952.2.0-alt1102.11.0-alt0.c9.1ALT-PU-2017-1777-1184645Fixed
thunderbirdp852.3.0-alt0.M80P.160.8.0-alt0.M80P.1ALT-PU-2017-2238-1188382Fixed
thunderbirdc10f152.2.0-alt1115.9.0-alt0.c10.1ALT-PU-2017-1777-1184645Fixed
thunderbirdc9f252.2.0-alt1102.11.0-alt0.c9.1ALT-PU-2017-1777-1184645Fixed
thunderbirdc760.8.0-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2019-2345-1234994Fixed
thunderbirdp1152.2.0-alt1115.9.0-alt1ALT-PU-2017-1777-1184645Fixed

References to Advisories, Solutions, and Tools

Vulnerability Status
Подтверждена производителем
Presence of an exploit
Данные уточняются
Fix status
Уязвимость устранена
Software Type
Операционная система, Прикладное ПО информационных систем
Solution
Использование рекомендаций:
Для продуктов Mozilla:
https://www.mozilla.org/security/advisories/mfsa2017-15/
https://www.mozilla.org/security/advisories/mfsa2017-16/
https://www.mozilla.org/security/advisories/mfsa2017-17/

Для Debian:
https://www.debian.org/security/2017/dsa-3881	 
https://www.debian.org/security/2017/dsa-3918

Для продуктов Red Hat:
https://access.redhat.com/security/cve/CVE-2017-5472

Для продуктов Novell Inc.:
https://www.suse.com/security/cve/CVE-2017-5472/

Для Astra Linux:
https://wiki.astralinux.ru/pages/viewpage.action?pageId=1212483
https://wiki.astralinux.ru/astra-linux-se15-bulletin-20201201SE15

Для Альт Линукс:
https://cve.basealt.ru/

Для Ubuntu:
https://ubuntu.com/security/notices/USN-3315-1?_ga=2.253574793.1874363206.1609607440-1543702552.1605094901
https://ubuntu.com/security/notices/USN-3321-1?_ga=2.253574793.1874363206.1609607440-1543702552.1605094901
Sources
https://nvd.nist.gov/vuln/detail/CVE-2017-5472
https://security-tracker.debian.org/tracker/CVE-2017-5472
https://www.mozilla.org/security/advisories/mfsa2017-15/
https://www.mozilla.org/security/advisories/mfsa2017-16/
https://www.mozilla.org/security/advisories/mfsa2017-17/
https://www.debian.org/security/2017/dsa-3881	 
https://www.debian.org/security/2017/dsa-3918
https://access.redhat.com/security/cve/CVE-2017-5472
https://www.suse.com/security/cve/CVE-2017-5472/
https://wiki.astralinux.ru/pages/viewpage.action?pageId=1212483
https://wiki.astralinux.ru/astra-linux-se15-bulletin-20201201SE15
https://cve.basealt.ru/
https://ubuntu.com/security/notices/USN-3315-1?_ga=2.253574793.1874363206.1609607440-1543702552.1605094901
https://ubuntu.com/security/notices/USN-3321-1?_ga=2.253574793.1874363206.1609607440-1543702552.1605094901
Other system identifiers