Bug 1029822 (CVE-2017-5428) - VUL-0: CVE-2017-5428: MozillaFirefox: overflow in createImageBitmap (MFSA 2017-08)
Summary: VUL-0: CVE-2017-5428: MozillaFirefox: overflow in createImageBitmap (MFSA 201...
Status: RESOLVED FIXED
Alias: CVE-2017-5428
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 42.2
: P3 - Medium : Major
Target Milestone: unspecified
Assignee: Wolfgang Rosenauer
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/181946/
Whiteboard: CVSSv2:SUSE:CVE-2017-5428:7.5:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2017-03-17 07:24 UTC by Wolfgang Rosenauer
Modified: 2022-02-13 10:58 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Rosenauer 2017-03-17 07:24:33 UTC
There is a "chemspill" release planned for Firefox 52 because of Pwn2Own.

Draft advisory:
## mfsa2017-08.yml
announced: March 17, 2017
impact: critical
fixed_in:
- Firefox 52.0.1
- Firefox ESR 52.0.1
title: integer overflow in createImageBitmap()
advisories:
  CVE-2017-5428:
    title: integer overflow in createImageBitmap()
    impact: critical
    reporter: Chaitin Security Research Lab via Trend Micro's Zero Day Initiative
    description: |
      An integer overflow in <code>createImageBitmap()</code> reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental <code>createImageBitmap</code> API. This function runs in the content sandbox, requiring  a second vulnerability to compromise a user's computer.
    bugs:
      - url: 1348168

Seems the code/revision is not yet available.
I will submit later today once it hopefully appears.
Comment 1 Petr Cerny 2017-03-17 16:12:07 UTC
Hm, they could put there a note on whether 45 is affected or not...
Comment 2 Petr Cerny 2017-03-17 16:12:49 UTC
Wolfgang, any chance you could cc me on the upstream bug so that I could check whether we'll need to patch 45 as well?
Comment 3 Wolfgang Rosenauer 2017-03-17 16:15:28 UTC
Not even I have access to that bug but on the sec-list it was confirmed that 45 is NOT affected.
Comment 4 Petr Cerny 2017-03-17 16:17:46 UTC
Perfect, thanks!
Comment 6 Andreas Stieger 2017-03-17 22:15:40 UTC
Public at https://www.mozilla.org/en-US/security/advisories/mfsa2017-08/#CVE-2017-5428

integer overflow in createImageBitmap()

Announced: March 17, 2017
Impact: critical
Products Firefox, Firefox ESR
Fixed in Firefox 52.0.1, Firefox ESR 52.0.1

#CVE-2017-5428: integer overflow in createImageBitmap()

Reporter: Chaitin Security Research Lab via Trend Micro's Zero Day Initiative
Impact: critical

Description

An integer overflow in createImageBitmap() was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the createImageBitmap API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer.
References

https://bugzilla.mozilla.org/show_bug.cgi?id=1348168
Comment 7 Bernhard Wiedemann 2017-03-17 23:01:24 UTC
This is an autogenerated message for OBS integration:
This bug (1029822) was mentioned in
https://build.opensuse.org/request/show/480954 42.2 / MozillaFirefox
https://build.opensuse.org/request/show/480955 42.1 / MozillaFirefox
Comment 8 Bernhard Wiedemann 2017-03-18 23:01:24 UTC
This is an autogenerated message for OBS integration:
This bug (1029822) was mentioned in
https://build.opensuse.org/request/show/481063 Factory / MozillaFirefox
Comment 9 Bernhard Wiedemann 2017-03-20 17:01:43 UTC
This is an autogenerated message for OBS integration:
This bug (1029822) was mentioned in
https://build.opensuse.org/request/show/481401 Factory / MozillaFirefox
Comment 10 Andreas Stieger 2017-03-20 19:29:13 UTC
released for Leap, submitted for Factory
Comment 11 Bernhard Wiedemann 2017-03-20 21:01:29 UTC
This is an autogenerated message for OBS integration:
This bug (1029822) was mentioned in
https://build.opensuse.org/request/show/481555 Factory / MozillaFirefox
Comment 12 Swamp Workflow Management 2017-03-20 23:09:31 UTC
openSUSE-SU-2017:0765-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1029822
CVE References: CVE-2017-5428
Sources used:
openSUSE Leap 42.2 (src):    MozillaFirefox-52.0.1-57.3.1
openSUSE Leap 42.1 (src):    MozillaFirefox-52.0.1-58.1