CVE Vulnerabilities

CVE-2017-5405

DEPRECATED: Use of Uninitialized Resource

Published: Jun 11, 2018 | Modified: Nov 25, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
5.1 LOW
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
5.6 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

Weakness

This entry has been deprecated because it was a duplicate of CWE-908. All content has been transferred to CWE-908.

Affected Software

NameVendorStart VersionEnd Version
Debian_linuxDebian8.0 (including)8.0 (including)
Red Hat Enterprise Linux 5RedHatfirefox-0:45.8.0-2.el5_11*
Red Hat Enterprise Linux 5RedHatthunderbird-0:45.8.0-1.el5_11*
Red Hat Enterprise Linux 6RedHatfirefox-0:45.8.0-2.el6_8*
Red Hat Enterprise Linux 6RedHatthunderbird-0:45.8.0-1.el6_8*
Red Hat Enterprise Linux 7RedHatfirefox-0:52.0-4.el7_3*
Red Hat Enterprise Linux 7RedHatthunderbird-0:45.8.0-1.el7_3*
FirefoxUbuntuprecise*
FirefoxUbuntutrusty*
FirefoxUbuntuupstream*
FirefoxUbuntuxenial*
FirefoxUbuntuyakkety*
FirefoxUbuntuzesty*
ThunderbirdUbuntudevel*
ThunderbirdUbuntuprecise*
ThunderbirdUbuntutrusty*
ThunderbirdUbuntuupstream*
ThunderbirdUbuntuxenial*
ThunderbirdUbuntuyakkety*
ThunderbirdUbuntuzesty*

References