CVE-2018-5147: Critical severity firefox vulnerability
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.
Other sources
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms.Update: The 52.7.2 source release accidentally did not include this patch (the Mozilla-produced 52.7.2 binaries are fine). Anyone building 52.7.2 on ARM should use revision 5cd5586a2f48424a9031a3fa4c782954a9df9a52 instead of the released source.
— Mozilla
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this flaw?
The vulnerability ID of this flaw is CVE-2018-5147.
What is the severity of CVE-2018-5147?
The severity of CVE-2018-5147 is critical with a severity value of 9.
Which software is affected by CVE-2018-5147?
Mozilla Firefox, Mozilla Firefox ESR, and Debian Linux are affected by CVE-2018-5147.
How do I fix CVE-2018-5147?
To fix CVE-2018-5147, you should update Mozilla Firefox to version 59.0.1 or later.
Where can I find more information about CVE-2018-5147?
You can find more information about CVE-2018-5147 on Bugzilla Mozilla, Mozilla Security Advisories, and SecurityFocus.