SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-5405

This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

MEDIUM 5.3EPSS 2.60%

Does this matter?

Lower severity and a low EPSS score (2.60%). Track it; it rarely justifies an emergency change on its own.

Description

Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
2.60% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-1187
Affected
debian/debian linux · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux workstation · mozilla/firefox · mozilla/thunderbird
Source
security@mozilla.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.