First published: Fri Mar 16 2018(Updated: )
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <59.0.1 | 59.0.1 |
Mozilla Firefox ESR | <52.7.2 | 52.7.2 |
<59.0.1 | 59.0.1 | |
<52.7.2 | 52.7.2 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Mozilla Firefox | <59.0.1 | |
Mozilla Firefox ESR | <52.7.2 | |
debian/firefox | 121.0-2 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.6.0esr-1~deb10u1 102.15.0esr-1~deb11u1 115.6.0esr-1~deb11u1 115.5.0esr-1~deb12u1 115.6.0esr-1~deb12u1 115.6.0esr-1 | |
debian/libvorbisidec | 1.2.1+git20180316-3 1.2.1+git20180316-7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this flaw is CVE-2018-5147.
The severity of CVE-2018-5147 is critical with a severity value of 9.
Mozilla Firefox, Mozilla Firefox ESR, and Debian Linux are affected by CVE-2018-5147.
To fix CVE-2018-5147, you should update Mozilla Firefox to version 59.0.1 or later.
You can find more information about CVE-2018-5147 on Bugzilla Mozilla, Mozilla Security Advisories, and SecurityFocus.