The package firefox before version 54.0-1 is vulnerable to multiple issues including arbitrary code execution, denial of service, information disclosure and content spoofing.
Arch Linux Security Advisory ASA-201706-19
=========================================
Severity: Critical
Date : 2017-06-16
CVE-ID : CVE-2017-5470 CVE-2017-5471 CVE-2017-5472 CVE-2017-7749
CVE-2017-7750 CVE-2017-7751 CVE-2017-7752 CVE-2017-7754
CVE-2017-7756 CVE-2017-7757 CVE-2017-7758 CVE-2017-7762
CVE-2017-7764 CVE-2017-7771 CVE-2017-7772 CVE-2017-7773
CVE-2017-7774 CVE-2017-7775 CVE-2017-7776 CVE-2017-7777
CVE-2017-7778
Package : firefox
Type : multiple issues
Remote : Yes
Link : https://security.archlinux.org/AVG-302
Summary
======
The package firefox before version 54.0-1 is vulnerable to multiple
issues including arbitrary code execution, denial of service,
information disclosure and content spoofing.
Resolution
=========
Upgrade to 54.0-1.
# pacman -Syu "firefox>=54.0-1"
The problems have been fixed upstream in version 54.0.
Workaround
=========
None.
Description
==========
- CVE-2017-5470 (arbitrary code execution)
Several memory safety issues leading to arbitrary code execution have
been found in Firefox < 54.0 and Thunderbird < 52.2.
- CVE-2017-5471 (arbitrary code execution)
Several memory safety issues leading to arbitrary code execution have
been found in Firefox < 54.0.
- CVE-2017-5472 (arbitrary code execution)
A use-after-free vulnerability has been found in Firefox < 54.0 and
Thunderbird < 52.2, in the frameloader during tree reconstruction while
regenerating CSS layout when attempting to use a node in the tree that
no longer exists.
- CVE-2017-7749 (arbitrary code execution)
A user-after-free has been found in Firefox < 54.0 and Thunderbird <
52.2, when using an incorrect URL during the reloading of a docshell.
- CVE-2017-7750 (arbitrary code execution)
A use-after-free has been found in Firefox < 54.0 and Thunderbird <
52.2, during video control operations when a