CVE-2018-5146: High severity Google Android vulnerability
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest.
Other sources
As per upstream advisory:
An out of bounds write while processing vorbis audio data was reported through the Pwn2Own contest.
— Red Hat
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-5146?
CVE-2018-5146 is a vulnerability that allows an out of bounds memory write while processing Vorbis audio data in Firefox, Firefox ESR, and Thunderbird.
Which software versions are affected by CVE-2018-5146?
Firefox versions earlier than 59.0.1, Firefox ESR versions earlier than 52.7.2, and Thunderbird versions earlier than 52.7 are affected by CVE-2018-5146.
What is the severity of CVE-2018-5146?
CVE-2018-5146 has a severity rating of 8.8 (Critical).
How can I fix CVE-2018-5146?
To fix CVE-2018-5146, update your Firefox version to 59.0.1 or later, Firefox ESR version to 52.7.2 or later, and Thunderbird version to 52.7 or later.
Where can I find more information about CVE-2018-5146?
You can find more information about CVE-2018-5146 at the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1446062), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2018-09/), and [SecurityFocus](http://www.securityfocus.com/bid/103432).