Vulnerability Description
Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 8.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Mozilla | Firefox | < 60.1.0 |
| Mozilla | Thunderbird | < 60.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/104556Third Party AdvisoryVDB Entry
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1461324%2C1414829%2C1395246%2C14Issue TrackingVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201810-01Third Party Advisory
- https://security.gentoo.org/glsa/201811-13Third Party Advisory
- https://usn.ubuntu.com/3705-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4295Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-15/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-16/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-19/Vendor Advisory
- http://www.securityfocus.com/bid/104556Third Party AdvisoryVDB Entry
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1461324%2C1414829%2C1395246%2C14Issue TrackingVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201810-01Third Party Advisory
- https://security.gentoo.org/glsa/201811-13Third Party Advisory
FAQ
What is CVE-2018-5187?
CVE-2018-5187 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run...
How severe is CVE-2018-5187?
CVE-2018-5187 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-5187?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Canonical Ubuntu Linux, Mozilla Firefox, Mozilla Thunderbird.