PT-2018-3099 · Mozilla+5 · Firefox Esr+7
Alex Gaynor
+8
·
Publicado
2018-06-26
·
Atualizado
2024-12-12
·
CVE-2018-5188
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Firefox versions 60 and earlier
Firefox ESR versions 60 and earlier, 52.8 and earlier
Thunderbird versions 60 and earlier, 52.9 and earlier
Description
The issue is caused by memory safety bugs, including buffer overflow in memory, which can lead to memory corruption. It is presumed that with sufficient effort, some of these bugs could be exploited to run arbitrary code. This can be achieved by a remote attacker using a specially crafted web page.
Recommendations
For Firefox versions 60 and earlier, update to version 61 or later.
For Firefox ESR versions 60 and earlier, update to version 60.1 or later.
For Firefox ESR versions 52.8 and earlier, update to version 52.9 or later.
For Thunderbird versions 60 and earlier, update to version 60.1 or later.
For Thunderbird versions 52.9 and earlier, update to version 52.9.1 or later.
As a temporary workaround, consider restricting access to potentially vulnerable web pages until a patch is available.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Ubuntu