Vulnerability BDU:2023-01886: Information

Description

Уязвимость браузера Mozilla Firefox ESR и почтового клиента Thunderbird, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код

Severity: CRITICAL (9.8) Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: March 13, 2018
Modified: March 13, 2018
Error type identifier: CWE-119

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus53.0.2-alt1127.0-alt1ALT-PU-2017-1577-1182567Fixed
firefoxp1053.0.2-alt1118.0.2-alt0.p10.1ALT-PU-2017-1577-1182567Fixed
firefoxp953.0.2-alt1105.0.1-alt0.c9.1ALT-PU-2017-1577-1182567Fixed
firefoxp853.0.2-alt0.M80P.168.0.1-alt0.M80P.1ALT-PU-2017-1579-1182593Fixed
firefoxc10f153.0.2-alt1112.0.2-alt0.p10.1ALT-PU-2017-1577-1182567Fixed
firefoxc9f253.0.2-alt1105.0.1-alt0.c9.1ALT-PU-2017-1577-1182567Fixed
firefoxc752.7.3-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2018-1583-1203884Fixed
firefoxp1153.0.2-alt1126.0.1-alt1ALT-PU-2017-1577-1182567Fixed
firefox-esrsisyphus52.7.0-alt1115.11.0-alt1ALT-PU-2018-1402-1201647Fixed
firefox-esrp1052.7.0-alt1115.11.0-alt1ALT-PU-2018-1402-1201647Fixed
firefox-esrp952.7.0-alt1102.11.0-alt0.c9.1ALT-PU-2018-1402-1201647Fixed
firefox-esrp852.7.0-alt0.M80P.168.4.1-alt0.M80P.1ALT-PU-2018-1403-1201658Fixed
firefox-esrc10f152.7.0-alt1115.9.1-alt0.c10.1ALT-PU-2018-1402-1201647Fixed
firefox-esrc9f252.7.0-alt1102.12.0-alt0.c9.1ALT-PU-2018-1402-1201647Fixed
firefox-esrp1152.7.0-alt1115.11.0-alt1ALT-PU-2018-1402-1201647Fixed
thunderbirdsisyphus52.7.0-alt1115.9.0-alt1ALT-PU-2018-1481-1202882Fixed
thunderbirdp1052.7.0-alt1115.9.0-alt1ALT-PU-2018-1481-1202882Fixed
thunderbirdp952.7.0-alt1102.11.0-alt0.c9.1ALT-PU-2018-1481-1202882Fixed
thunderbirdp852.7.0-alt0.M80P.160.8.0-alt0.M80P.1ALT-PU-2018-1483-1202900Fixed
thunderbirdc10f152.7.0-alt1115.9.0-alt0.c10.1ALT-PU-2018-1481-1202882Fixed
thunderbirdc9f252.7.0-alt1102.11.0-alt0.c9.1ALT-PU-2018-1481-1202882Fixed
thunderbirdc760.8.0-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2019-2345-1234994Fixed
thunderbirdp1152.7.0-alt1115.9.0-alt1ALT-PU-2018-1481-1202882Fixed

References to Advisories, Solutions, and Tools

Vulnerability Status
Подтверждена производителем
Presence of an exploit
Данные уточняются
Fix status
Уязвимость устранена
Software Type
Операционная система, Прикладное ПО информационных систем
Solution
Использование рекомендаций:
Для продуктов Mozilla Corp.:
https://www.mozilla.org/security/advisories/mfsa2018-07/	
https://www.mozilla.org/security/advisories/mfsa2018-09/

Для Debian GNU/Linux:
https://lists.debian.org/debian-lts-announce/2018/03/msg00010.html	
https://lists.debian.org/debian-lts-announce/2018/03/msg00029.html	
https://www.debian.org/security/2018/dsa-4139	
https://www.debian.org/security/2018/dsa-4155

Для Ubuntu:
https://ubuntu.com/security/notices/USN-3545-1

Для Red Hat Inc.:
https://access.redhat.com/security/cve/CVE-2018-5145
Sources
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1261175%2C1348955
https://lists.debian.org/debian-lts-announce/2018/03/msg00010.html
https://lists.debian.org/debian-lts-announce/2018/03/msg00029.html
https://security.gentoo.org/glsa/201811-13 
https://usn.ubuntu.com/3545-1/
https://www.debian.org/security/2018/dsa-4139
https://www.debian.org/security/2018/dsa-4155
https://www.mozilla.org/security/advisories/mfsa2018-07/
https://www.mozilla.org/security/advisories/mfsa2018-09/
Other system identifiers