CVE-2017-5428

Publication date 20 March 2017

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

Description

An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.

Status

Package Ubuntu Release Status
firefox 17.04 zesty
Fixed 52.0.1+build2-0ubuntu1
16.10 yakkety
Fixed 52.0.1+build2-0ubuntu0.16.10.1
16.04 LTS xenial
Fixed 52.0.1+build2-0ubuntu0.16.04.1
14.04 LTS trusty
Fixed 52.0.1+build2-0ubuntu0.14.04.1
12.04 LTS precise
Fixed 52.0.1+build2-0ubuntu0.12.04.1

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.8 · Critical

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Related Ubuntu Security Notices (USN)

Other references


Access our resources on patching vulnerabilities