Number: AV17-035
Date: 21 March 2017
Purpose
The purpose of this advisory is to raise awareness of a vulnerability in Mozilla Firefox and Firefox ESR for which updates are now available.
Assessment
Mozilla released security updates to address integer overflow vulnerability in Firefox and Firefox ESR. The severity of the issue is critical.
Versions affected:
Firefox: versions prior to 52.0.1
Firefox ESR: versions prior to 52.0.1
CVE Reference: CVE-2017-5428
Suggested Action
CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.
References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-08/