PT-2018-3099 · Mozilla+5 · Firefox Esr+7

Alex Gaynor

+8

·

Published

2018-06-26

·

Updated

2024-12-12

·

CVE-2018-5188

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions 60 and earlier Firefox ESR versions 60 and earlier, 52.8 and earlier Thunderbird versions 60 and earlier, 52.9 and earlier
Description The issue is caused by memory safety bugs, including buffer overflow in memory, which can lead to memory corruption. It is presumed that with sufficient effort, some of these bugs could be exploited to run arbitrary code. This can be achieved by a remote attacker using a specially crafted web page.
Recommendations For Firefox versions 60 and earlier, update to version 61 or later. For Firefox ESR versions 60 and earlier, update to version 60.1 or later. For Firefox ESR versions 52.8 and earlier, update to version 52.9 or later. For Thunderbird versions 60 and earlier, update to version 60.1 or later. For Thunderbird versions 52.9 and earlier, update to version 52.9.1 or later. As a temporary workaround, consider restricting access to potentially vulnerable web pages until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1952
ALT-PU-2018-1978
ALT-PU-2018-1985
ALT-PU-2018-2669
ALT-PU-2019-2324
ALT-PU-2019-2486
BDU:2019-04024
CESA-2018_2112
CESA-2018_2113
CESA-2018_2251
CESA-2018_2252
CVE-2018-5188
DLA-1406-1
DLA-1425-1
DSA-4235-1
DSA-4244-1
MGASA-2018-0305
MGASA-2018-0316
MGASA-2018-0321
MGASA-2018-0480
OPENSUSE-SU-2018:2807-1
OPENSUSE-SU-2018:3687-1
OPENSUSE-SU-2018_1833-1
OPENSUSE-SU-2018_1905-1
OPENSUSE-SU-2018_2330-1
OPENSUSE-SU-2018_2658-1
OPENSUSE-SU-2018_3051-1
OPENSUSE-SU-2024:10590-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
RHSA-2018:2112
RHSA-2018:2113
RHSA-2018:2251
RHSA-2018:2252
RHSA-2018_2112
RHSA-2018_2113
RHSA-2018_2251
RHSA-2018_2252
SUSE-SU-2018:2174-1
SUSE-SU-2018:2298-1
SUSE-SU-2018:2322-1
SUSE-SU-2018:2322-2
SUSE-SU-2018:2325-1
SUSE-SU-2018:3247-1
USN-3705-1
USN-3705-2
USN-3714-1
USN-3749-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird
Ubuntu