SVG Content Processing Out-of-Bounds Read Vulnerability

SVG Content Processing Out-of-Bounds Read Vulnerability

CVE-2017-5465 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:P

An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Learn more about our Web Application Penetration Testing UK.