An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the reading of random memory containing matches to specifically set patterns. This vulnerability affects Firefox < 52 and Thunderbird < 52.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2017-09/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2017-05/ | vendor advisory |
http://www.securitytracker.com/id/1037966 | third party advisory vdb entry |
http://www.securityfocus.com/bid/96692 | third party advisory vdb entry |
https://bugzilla.mozilla.org/show_bug.cgi?id=1338876 | patch exploit vendor advisory issue tracking |