Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-5129

Опубликовано: 11 июн. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 8.6

Описание

A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.

РелизСтатусПримечание
artful

released

59.0+build5-0ubuntu0.17.10.1
bionic

released

59.0.1+build1-0ubuntu1
devel

released

59.0.1+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [59.0+build5-0ubuntu0.14.04.1]]
precise/esm

DNE

trusty

released

59.0+build5-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [59.0+build5-0ubuntu0.14.04.1]
upstream

released

59.0
xenial

released

59.0+build5-0ubuntu0.16.04.1

Показывать по

РелизСтатусПримечание
artful

released

1:52.7.0+build1-0ubuntu0.17.10.1
bionic

released

1:52.7.0+build1-0ubuntu1
devel

released

1:52.7.0+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:52.7.0+build1-0ubuntu0.14.04.1]]
precise/esm

DNE

trusty

released

1:52.7.0+build1-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [1:52.7.0+build1-0ubuntu0.14.04.1]
upstream

released

52.7.0
xenial

released

1:52.7.0+build1-0ubuntu0.16.04.1

Показывать по

5 Medium

CVSS2

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
redhat
больше 7 лет назад

A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.

CVSS3: 8.6
nvd
около 7 лет назад

A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.

CVSS3: 8.6
debian
около 7 лет назад

A lack of parameter validation on IPC messages results in a potential ...

CVSS3: 8.6
github
около 3 лет назад

A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.

CVSS3: 8.6
fstec
больше 7 лет назад

Уязвимость браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с отсутствием проверки параметров в IPC-сообщениях, позволяющая нарушителю оказать воздействие на целостность данных

5 Medium

CVSS2

8.6 High

CVSS3