CVE-2017-7813

Publication date

2018-06-11 21:00:00

Family

mozilla

State

PUBLISHED

Description

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.