| Title | Firefox および Thunderbird における解放済みメモリの使用に関する脆弱性 |
|---|---|
| Summary | Firefox および Thunderbird には、解放済みメモリの使用に関する脆弱性が存在します。 |
| Possible impacts | サービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | March 7, 2017, midnight |
| Registration Date | Aug. 17, 2018, 2:19 p.m. |
| Last Update | Aug. 17, 2018, 2:19 p.m. |
| CVSS3.0 : 重要 | |
| Score | 7.5 |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS2.0 : 警告 | |
| Score | 5 |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| Mozilla Foundation |
| Mozilla Firefox 52 未満 |
| Mozilla Thunderbird 52 未満 |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2018年08月17日] 掲載 |
Aug. 17, 2018, 2:19 p.m. |
| Summary | A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while still in use in some circumstances, leading to a potentially exploitable crash. Note: This issue is in "libGLES", which is only in use on Windows. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52. |
|---|---|
| Publication Date | June 12, 2018, 6:29 a.m. |
| Registration Date | Jan. 26, 2021, 1:25 p.m. |
| Last Update | Nov. 21, 2024, 12:27 p.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | 52.0 | ||||
| execution environment | |||||
| 1 | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* | ||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | 52.0 | ||||
| execution environment | |||||
| 1 | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* | ||||