Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5154

Опубликовано: 11 июн. 2018
Источник: debian
EPSS Низкий

Описание

A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed60.0-1package
firefox-esrfixed52.8.0esr-1package
thunderbirdfixed1:52.8.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/#CVE-2018-5154

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5154

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/#CVE-2018-5154

EPSS

Процентиль: 86%
0.03073
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 9.8
redhat
больше 7 лет назад

A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 9.8
nvd
больше 7 лет назад

A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 9.8
github
больше 3 лет назад

A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость механизма обработки SVG-объектов браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 86%
0.03073
Низкий