PT-2018-3595 · Mozilla+5 · Firefox Esr+6

Tony Paloma

·

Publicado

2018-01-24

·

Atualizado

2024-12-12

·

CVE-2018-5130

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 59 Firefox-ESR versions prior to 52.7
Description The issue is related to the implementation of WebRTC technology in Mozilla Firefox and Firefox-ESR browsers, specifically concerning the mismatched RTP payload type of sent data packets. This can potentially lead to a crash when packets with a mismatched RTP payload type are sent in WebRTC connections. Exploitation of this issue may allow a remote attacker to cause a denial of service.
Recommendations For Firefox versions prior to 59, update to version 59 or later to resolve the issue. For Firefox-ESR versions prior to 52.7, update to version 52.7 or later to resolve the issue.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1502
ALT-PU-2018-1854
BDU:2021-00396
CESA-2018_0526
CESA-2018_0527
CVE-2018-5130
DLA-1308-1
DSA-4139-1
MGASA-2018-0202
MGASA-2018-0338
OPENSUSE-SU-2018_0681-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2018:0526
RHSA-2018:0527
RHSA-2018_0526
RHSA-2018_0527
SUSE-SU-2018:0850-1
SUSE-SU-2018:0907-1
USN-3596-1
USN-3596-2

Produtos afetados

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Ubuntu