CVE-2018-5129: High severity Mozilla Thunderbird vulnerability
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-5129?
The severity of CVE-2018-5129 is high with a CVSS score of 8.6.
Which software is affected by CVE-2018-5129?
CVE-2018-5129 affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
How does CVE-2018-5129 exploit work?
CVE-2018-5129 exploits a lack of parameter validation on IPC messages, allowing a potential out-of-bounds write through malformed IPC messages.
Can CVE-2018-5129 lead to sandbox escape?
Yes, CVE-2018-5129 can potentially allow for sandbox escape through memory corruption in the parent process.
How can I mitigate CVE-2018-5129 vulnerability?
To mitigate CVE-2018-5129, make sure to update Thunderbird to version 52.7 or higher, Firefox ESR to version 52.7 or higher, and Firefox to version 59 or higher.