Vulnerability BDU:2021-00021: Information

Description

Уязвимость браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная c использованием памяти после освобождения, позволяющая нарушителю вызвать отказ в обслуживании

Severity: CRITICAL (9.8) Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: Sept. 13, 2017
Modified: Sept. 13, 2017
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus58.0.2-alt1126.0.1-alt1ALT-PU-2018-1178-1200448Fixed
firefoxp1058.0.2-alt1118.0.2-alt0.p10.1ALT-PU-2018-1178-1200448Fixed
firefoxp958.0.2-alt1105.0.1-alt0.c9.1ALT-PU-2018-1178-1200448Fixed
firefoxp858.0.2-alt0.M80P.168.0.1-alt0.M80P.1ALT-PU-2018-1221-1200523Fixed
firefoxc10f158.0.2-alt1112.0.2-alt0.p10.1ALT-PU-2018-1178-1200448Fixed
firefoxc9f258.0.2-alt1105.0.1-alt0.c9.1ALT-PU-2018-1178-1200448Fixed
firefoxc760.6.1-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2019-1726-1218597Fixed
firefoxp1158.0.2-alt1126.0.1-alt1ALT-PU-2018-1178-1200448Fixed
firefox-esrsisyphus60.0.1-alt1115.11.0-alt1ALT-PU-2018-1854-1207816Fixed
firefox-esrp1060.0.1-alt1115.11.0-alt1ALT-PU-2018-1854-1207816Fixed
firefox-esrp960.0.1-alt1102.11.0-alt0.c9.1ALT-PU-2018-1854-1207816Fixed
firefox-esrp860.1.0-alt0.M80P.168.4.1-alt0.M80P.1ALT-PU-2018-1966-1207865Fixed
firefox-esrc10f160.0.1-alt1115.9.1-alt0.c10.1ALT-PU-2018-1854-1207816Fixed
firefox-esrc9f260.0.1-alt1102.12.0-alt0.c9.1ALT-PU-2018-1854-1207816Fixed
firefox-esrp1160.0.1-alt1115.11.0-alt1ALT-PU-2018-1854-1207816Fixed
thunderbirdsisyphus52.6.0-alt1115.9.0-alt1ALT-PU-2018-1101-1198679Fixed
thunderbirdp1052.6.0-alt1115.9.0-alt1ALT-PU-2018-1101-1198679Fixed
thunderbirdp952.6.0-alt1102.11.0-alt0.c9.1ALT-PU-2018-1101-1198679Fixed
thunderbirdp852.6.0-alt0.M80P.160.8.0-alt0.M80P.1ALT-PU-2018-1102-1198696Fixed
thunderbirdc10f152.6.0-alt1115.9.0-alt0.c10.1ALT-PU-2018-1101-1198679Fixed
thunderbirdc9f252.6.0-alt1102.11.0-alt0.c9.1ALT-PU-2018-1101-1198679Fixed
thunderbirdc760.8.0-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2019-2345-1234994Fixed
thunderbirdp1152.6.0-alt1115.9.0-alt1ALT-PU-2018-1101-1198679Fixed

References to Advisories, Solutions, and Tools

Vulnerability Status
Подтверждена производителем
Presence of an exploit
Данные уточняются
Fix status
Уязвимость устранена
Software Type
Операционная система, Прикладное ПО информационных систем
Solution
Использование рекомендаций:
Для продуктов Mozilla:
https://www.mozilla.org/security/advisories/mfsa2018-02/	
https://www.mozilla.org/security/advisories/mfsa2018-03/	
https://www.mozilla.org/security/advisories/mfsa2018-04/

Для продуктов Novell Inc.:
https://www.suse.com/security/cve/CVE-2018-5098/

Для Astra Linux:
https://wiki.astralinux.ru/pages/viewpage.action?pageId=1212483
https://wiki.astralinux.ru/astra-linux-se15-bulletin-20201201SE15

Для Альт Линукс:
https://cve.basealt.ru/

Для Debian: 
https://www.debian.org/security/2018/dsa-4096	 
https://www.debian.org/security/2018/dsa-4102
https://lists.debian.org/debian-lts-announce/2018/01/msg00030.html	
https://lists.debian.org/debian-lts-announce/2018/01/msg00036.html	

Для Ubuntu:
https://usn.ubuntu.com/usn/usn-3544-1
https://usn.ubuntu.com/usn/usn-3529-1

Для продуктов Red Hat:
https://access.redhat.com/security/cve/cve-2018-5098
Sources
https://nvd.nist.gov/vuln/detail/CVE-2018-5098
https://security-tracker.debian.org/tracker/CVE-2018-5098
https://www.mozilla.org/security/advisories/mfsa2018-02/	
https://www.mozilla.org/security/advisories/mfsa2018-03/	
https://www.mozilla.org/security/advisories/mfsa2018-04/
https://www.suse.com/security/cve/CVE-2018-5098/
https://wiki.astralinux.ru/pages/viewpage.action?pageId=1212483
https://wiki.astralinux.ru/astra-linux-se15-bulletin-20201201SE15
https://cve.basealt.ru/
https://www.debian.org/security/2018/dsa-4096	 
https://www.debian.org/security/2018/dsa-4102
https://lists.debian.org/debian-lts-announce/2018/01/msg00030.html	
https://lists.debian.org/debian-lts-announce/2018/01/msg00036.html	
https://usn.ubuntu.com/usn/usn-3544-1
https://usn.ubuntu.com/usn/usn-3529-1	
https://access.redhat.com/security/cve/cve-2018-5098
Other system identifiers