vendor:
Firefox
by:
Rh0
7.5
CVSS
HIGH
ASLR and DEP Bypass
119
CWE
Product Name: Firefox
Affected Version From: Firefox 50.0.1
Affected Version To: Firefox 50.0.1
Patch Exists: NO
Related CWE: CVE-2017-5375, CVE-2016-9079
CPE: a:mozilla:firefox:50.0.1
Metasploit:
https://www.rapid7.com/db/vulnerabilities/mfsa2017-01-cve-2017-5375/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2017-5375/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2017-5375/, https://www.rapid7.com/db/vulnerabilities/ubuntu-usn-3175-2/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2017-5375/, https://www.rapid7.com/db/vulnerabilities/mozilla-thunderbird-cve-2017-5375/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2017-5375/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2017-5375/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2017-5375/, https://www.rapid7.com/db/vulnerabilities/mfsa2017-02-cve-2017-5375/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2017-5375/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2017-5375/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2017-5375/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2017-5375/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2016-9079/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp1-cve-2016-9079/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2016-9079/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2016-9079/, https://www.rapid7.com/db/vulnerabilities/mozilla-thunderbird-cve-2016-9079/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2016-9079/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-9079/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2016-9079/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2016-9079/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2016-9079/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2016-9079/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2016-9079/, https://www.rapid7.com/db/vulnerabilities/mfsa2016-92-cve-2016-9079/
Platforms Tested: Windows 8.1, Windows 10
2017
FULL ASLR AND DEP BYPASS USING ASM.JS JIT SPRAY (CVE-2017-5375)
This exploit bypasses Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP) using the ASM.JS JIT Spray technique. It targets Firefox version 50.0.1 and exploits a vulnerability (CVE-2016-9079) in the Tor Browser.
Mitigation:
To mitigate this vulnerability, users should update to a patched version of the affected software.