Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5146

Опубликовано: 11 июн. 2018
Источник: debian
EPSS Средний

Описание

An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed59.0.1-1package
firefox-esrfixed52.7.2esr-1package
thunderbirdfixed1:52.7.0-1package
libvorbisfixed1.3.5-4.2package

Примечания

  • https://github.com/xiph/vorbis/commit/667ceb4aab60c1f74060143bb24e5f427b3cce5f (v1.3.6)

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-08/

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-09/

EPSS

Процентиль: 96%
0.26243
Средний

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 7 лет назад

An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.

CVSS3: 8.8
redhat
больше 7 лет назад

An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.

CVSS3: 8.8
nvd
около 7 лет назад

An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.

suse-cvrf
больше 7 лет назад

Security update for libvorbis

suse-cvrf
больше 7 лет назад

Security update for MozillaFirefox

EPSS

Процентиль: 96%
0.26243
Средний