Vulnerability CVE-2018-5125: Information

Description

Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.

Severity: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: June 12, 2018
Modified: March 8, 2019
Error type identifier: CWE-119

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus59.0.2-alt1126.0.1-alt1ALT-PU-2018-1502-1203049Fixed
firefoxp1059.0.2-alt1118.0.2-alt0.p10.1ALT-PU-2018-1502-1203049Fixed
firefoxp959.0.2-alt1105.0.1-alt0.c9.1ALT-PU-2018-1502-1203049Fixed
firefoxp859.0.2-alt1.M80P.168.0.1-alt0.M80P.1ALT-PU-2018-1553-1203220Fixed
firefoxc10f159.0.2-alt1112.0.2-alt0.p10.1ALT-PU-2018-1502-1203049Fixed
firefoxc9f259.0.2-alt1105.0.1-alt0.c9.1ALT-PU-2018-1502-1203049Fixed
firefoxc752.7.3-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2018-1583-1203884Fixed
firefoxp1159.0.2-alt1126.0.1-alt1ALT-PU-2018-1502-1203049Fixed
firefox-esrsisyphus60.0.1-alt1115.11.0-alt1ALT-PU-2018-1854-1207816Fixed
firefox-esrp1060.0.1-alt1115.11.0-alt1ALT-PU-2018-1854-1207816Fixed
firefox-esrp960.0.1-alt1102.11.0-alt0.c9.1ALT-PU-2018-1854-1207816Fixed
firefox-esrp860.1.0-alt0.M80P.168.4.1-alt0.M80P.1ALT-PU-2018-1966-1207865Fixed
firefox-esrc10f160.0.1-alt1115.9.1-alt0.c10.1ALT-PU-2018-1854-1207816Fixed
firefox-esrc9f260.0.1-alt1102.12.0-alt0.c9.1ALT-PU-2018-1854-1207816Fixed
firefox-esrp1160.0.1-alt1115.11.0-alt1ALT-PU-2018-1854-1207816Fixed
thunderbirdsisyphus52.7.0-alt1115.9.0-alt1ALT-PU-2018-1481-1202882Fixed
thunderbirdp1052.7.0-alt1115.9.0-alt1ALT-PU-2018-1481-1202882Fixed
thunderbirdp952.7.0-alt1102.11.0-alt0.c9.1ALT-PU-2018-1481-1202882Fixed
thunderbirdp852.7.0-alt0.M80P.160.8.0-alt0.M80P.1ALT-PU-2018-1483-1202900Fixed
thunderbirdc10f152.7.0-alt1115.9.0-alt0.c10.1ALT-PU-2018-1481-1202882Fixed
thunderbirdc9f252.7.0-alt1102.11.0-alt0.c9.1ALT-PU-2018-1481-1202882Fixed
thunderbirdc760.8.0-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2019-2345-1234994Fixed
thunderbirdp1152.7.0-alt1115.9.0-alt1ALT-PU-2018-1481-1202882Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

      Configuration 2

      cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
      End excliding
      59.0

      cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
      End excliding
      52.7.0

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
      End excliding
      52.7.0