CVE-2017-7773

MEDIUM

Description

Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.

References

https://www.mozilla.org/en-US/security/advisories/mfsa2017-15/

Details

Source: MITRE

Published: 2019-04-15

Updated: 2019-04-15

Type: CWE-119

Risk Information

CVSS v2.0

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3.0

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH

Tenable Plugins

View all (38 total)

IDNameProductFamilySeverity
127347NewStart CGSL MAIN 4.05 : thunderbird Multiple Vulnerabilities (NS-SA-2019-0110)NessusNewStart CGSL Local Security Checks
critical
127332NewStart CGSL MAIN 4.05 : firefox Multiple Vulnerabilities (NS-SA-2019-0103)NessusNewStart CGSL Local Security Checks
high
106884GLSA-201802-03 : Mozilla Firefox: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
104580Virtuozzo 7 : graphite2 / graphite2-devel (VZLSA-2017-1793)NessusVirtuozzo Local Security Checks
high
103848GLSA-201710-13 : Graphite: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
102679Ubuntu 14.04 LTS / 16.04 LTS / 17.04 : graphite2 vulnerabilities (USN-3398-1)NessusUbuntu Local Security Checks
high
102546Amazon Linux AMI : graphite2 (ALAS-2017-872)NessusAmazon Linux Local Security Checks
high
102240EulerOS 2.0 SP2 : graphite2 (EulerOS-SA-2017-1153)NessusHuawei Local Security Checks
high
102239EulerOS 2.0 SP1 : graphite2 (EulerOS-SA-2017-1152)NessusHuawei Local Security Checks
high
101983Debian DSA-3918-1 : icedove - security updateNessusDebian Local Security Checks
high
101925Scientific Linux Security Update : graphite2 on SL7.x x86_64 (20170721)NessusScientific Linux Local Security Checks
high
101907CentOS 7 : graphite2 (CESA-2017:1793)NessusCentOS Local Security Checks
high
101883RHEL 7 : graphite2 (RHSA-2017:1793)NessusRed Hat Local Security Checks
high
101878Oracle Linux 7 : graphite2 (ELSA-2017-1793)NessusOracle Linux Local Security Checks
high
101855EulerOS 2.0 SP2 : firefox (EulerOS-SA-2017-1127)NessusHuawei Local Security Checks
high
101854EulerOS 2.0 SP1 : firefox (EulerOS-SA-2017-1126)NessusHuawei Local Security Checks
high
101772Mozilla Thunderbird < 52.2 Multiple VulnerabilitiesNessusWindows
high
101771Mozilla Thunderbird < 52.2 Multiple Vulnerabilities (macOS)NessusMacOS X Local Security Checks
high
101485Virtuozzo 6 : thunderbird (VZLSA-2017-1561)NessusVirtuozzo Local Security Checks
high
101480Virtuozzo 7 : firefox (VZLSA-2017-1440)NessusVirtuozzo Local Security Checks
high
101261Ubuntu 14.04 LTS / 16.04 LTS / 16.10 / 17.04 : thunderbird vulnerabilities (USN-3321-1)NessusUbuntu Local Security Checks
high
101238Debian DLA-1013-1 : graphite2 security updateNessusDebian Local Security Checks
high
101208Debian DLA-1007-1 : icedove/thunderbird security updateNessusDebian Local Security Checks
high
101011Debian DSA-3894-1 : graphite2 - security updateNessusDebian Local Security Checks
high
100984Scientific Linux Security Update : thunderbird on SL6.x, SL7.x i386/x86_64 (20170621)NessusScientific Linux Local Security Checks
high
100978Oracle Linux 6 / 7 : thunderbird (ELSA-2017-1561)NessusOracle Linux Local Security Checks
high
100965CentOS 6 / 7 : thunderbird (CESA-2017:1561)NessusCentOS Local Security Checks
high
100950RHEL 6 / 7 : thunderbird (RHSA-2017:1561)NessusRed Hat Local Security Checks
high
100885openSUSE Security Update : Mozilla based packages (openSUSE-2017-712)NessusSuSE Local Security Checks
high
100851Debian DLA-991-1 : firefox-esr security updateNessusDebian Local Security Checks
high
100835Ubuntu 14.04 LTS / 16.04 LTS / 16.10 / 17.04 : firefox vulnerabilities (USN-3315-1)NessusUbuntu Local Security Checks
high
100815CentOS 6 / 7 : firefox (CESA-2017:1440)NessusCentOS Local Security Checks
high
100809Mozilla Firefox ESR < 52.2 Multiple VulnerabilitiesNessusWindows
high
100807Mozilla Firefox ESR < 52.2 Multiple Vulnerabilities (macOS)NessusMacOS X Local Security Checks
high
100802Scientific Linux Security Update : firefox on SL6.x, SL7.x i386/x86_64 (20170614)NessusScientific Linux Local Security Checks
high
100801RHEL 6 / 7 : firefox (RHSA-2017:1440)NessusRed Hat Local Security Checks
high
100800Oracle Linux 6 / 7 : firefox (ELSA-2017-1440)NessusOracle Linux Local Security Checks
high
100797Debian DSA-3881-1 : firefox-esr - security updateNessusDebian Local Security Checks
high