Vulnerability BDU:2019-04024: Information

Description

Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, вызванная выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код

Severity: CRITICAL (9.8) Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: July 26, 2018
Modified: July 26, 2018
Error type identifier: CWE-119

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus61.0-alt1126.0.1-alt1ALT-PU-2018-1985-1209471Fixed
firefoxp1061.0-alt1118.0.2-alt0.p10.1ALT-PU-2018-1985-1209471Fixed
firefoxp961.0-alt1105.0.1-alt0.c9.1ALT-PU-2018-1985-1209471Fixed
firefoxp861.0.1-alt0.M80P.168.0.1-alt0.M80P.1ALT-PU-2018-2036-1209591Fixed
firefoxc10f161.0-alt1112.0.2-alt0.p10.1ALT-PU-2018-1985-1209471Fixed
firefoxc9f261.0-alt1105.0.1-alt0.c9.1ALT-PU-2018-1985-1209471Fixed
firefoxc760.6.1-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2019-1726-1218597Fixed
firefoxp1161.0-alt1126.0.1-alt1ALT-PU-2018-1985-1209471Fixed
firefox-esrsisyphus60.1.0-alt1115.11.0-alt1ALT-PU-2018-1952-1209186Fixed
firefox-esrp1060.1.0-alt1115.11.0-alt1ALT-PU-2018-1952-1209186Fixed
firefox-esrp968.0.2-alt1102.11.0-alt0.c9.1ALT-PU-2019-2486-1235108Fixed
firefox-esrp860.1.0-alt0.M80P.168.4.1-alt0.M80P.1ALT-PU-2018-1966-1207865Fixed
firefox-esrc10f160.1.0-alt1115.9.1-alt0.c10.1ALT-PU-2018-1952-1209186Fixed
firefox-esrc9f268.0.2-alt1102.12.0-alt0.c9.1ALT-PU-2019-2486-1235108Fixed
firefox-esrp1160.1.0-alt1115.11.0-alt1ALT-PU-2018-1952-1209186Fixed
thunderbirdsisyphus52.9.0-alt1115.9.0-alt1ALT-PU-2018-1978-1209483Fixed
thunderbirdp1052.9.0-alt1115.9.0-alt1ALT-PU-2018-1978-1209483Fixed
thunderbirdp952.9.0-alt1102.11.0-alt0.c9.1ALT-PU-2018-1978-1209483Fixed
thunderbirdp852.9.0-alt0.M80P.160.8.0-alt0.M80P.1ALT-PU-2018-1988-1209501Fixed
thunderbirdc10f152.9.0-alt1115.9.0-alt0.c10.1ALT-PU-2018-1978-1209483Fixed
thunderbirdc9f252.9.0-alt1102.11.0-alt0.c9.1ALT-PU-2018-1978-1209483Fixed
thunderbirdc760.8.0-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2019-2345-1234994Fixed
thunderbirdp1152.9.0-alt1115.9.0-alt1ALT-PU-2018-1978-1209483Fixed

References to Advisories, Solutions, and Tools

Vulnerability Status
Подтверждена производителем
Presence of an exploit
Данные уточняются
Fix status
Уязвимость устранена
Software Type
Операционная система, Прикладное ПО информационных систем
Solution
Использование рекомендаций:
Для продуктов Mozilla:
https://www.mozilla.org/security/advisories/mfsa2018-15/
https://www.mozilla.org/security/advisories/mfsa2018-16/
https://www.mozilla.org/security/advisories/mfsa2018-17/
https://www.mozilla.org/security/advisories/mfsa2018-18/
https://www.mozilla.org/security/advisories/mfsa2018-19/
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1456189%2C1456975%2C1465898%2C1392739%2C1451297%2C1464063%2C1437842%2C1442722%2C1452576%2C1450688%2C1458264%2C1458270%2C1465108%2C1464829%2C1464079%2C1463494%2C1458048
 
Для Debian GNU/Linux:
https://lists.debian.org/debian-lts-announce/2018/06/msg00014.html
https://lists.debian.org/debian-lts-announce/2018/07/msg00013.html
https://www.debian.org/security/2018/dsa-4244

Для Астра Линукс:
https://wiki.astralinux.ru/pages/viewpage.action?pageId=57444186
https://wiki.astralinux.ru/astra-linux-se81-bulletin-20211019SE81

Для Ubuntu:
https://usn.ubuntu.com/3705-1/
https://usn.ubuntu.com/3714-1/
https://usn.ubuntu.com/3749-1/

 Для OpenSUSE:
https://www.suse.com/security/cve/CVE-2018-5188/

Для Red Hat:
https://access.redhat.com/security/cve/CVE-2018-5188 

Для Альт Линукс:
https://cve.basealt.ru/

Для ОС РОСА Кобальт:
http://wiki.rosalab.ru/ru/index.php/ROSA-SA-18-07-04.002
Sources
https://wiki.astralinux.ru/pages/viewpage.action?pageId=44892734
https://usn.ubuntu.com/3705-1/
https://usn.ubuntu.com/3714-1/
https://usn.ubuntu.com/3749-1/
https://www.debian.org/security/2018/dsa-4244
https://www.mozilla.org/en-US/security/advisories/mfsa2018-15/
https://www.mozilla.org/en-US/security/advisories/mfsa2018-16/
https://www.mozilla.org/en-US/security/advisories/mfsa2018-17/
https://www.mozilla.org/en-US/security/advisories/mfsa2018-18/
https://www.mozilla.org/en-US/security/advisories/mfsa2018-19/
https://bugzilla.redhat.com/show_bug.cgi?id=1595040
https://access.redhat.com/security/cve/cve-2018-5188
https://nvd.nist.gov/vuln/detail/CVE-2018-5188
https://www.securityfocus.com/bid/104555
https://www.cvedetails.com/cve/CVE-2018-5188/?q=CVE-2018-5188
http://wiki.rosalab.ru/ru/index.php/ROSA-SA-18-07-04.002
https://wiki.astralinux.ru/astra-linux-se81-bulletin-20211019SE81
Other system identifiers