CVE-2018-5153: High severity firefox vulnerability
Published May 9, 2018
·Updated
If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bounds read with the read memory sent to the originating server in response.
Affected Software
7 affected componentsFixes available
debian/firefox
131.0.2-2
Mozilla Firefox<60.0
Ubuntu=14.04
Ubuntu=16.04
Ubuntu=17.10
Ubuntu=18.04
Mozilla Firefox<60
60
Event History
May 9, 2018
CVE Published
12:00 AM
Jun 11, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:06 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:05 AM
RemedyDescriptionSeverityAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
Frequently Asked Questions
1
What is CVE-2018-5153?
CVE-2018-5153 is a vulnerability that allows websocket data sent with mixed text and binary in a single message to be corrupted, potentially resulting in an out-of-bounds read.
2
Which software is affected by CVE-2018-5153?
Firefox versions prior to 60 are affected by CVE-2018-5153.
3
What is the severity of CVE-2018-5153?
CVE-2018-5153 has a severity rating of 7.5 (high).
4
How can I fix CVE-2018-5153?
Update your Firefox browser to version 60 or higher to fix CVE-2018-5153.
5
Where can I find more information about CVE-2018-5153?
You can find more information about CVE-2018-5153 on the Mozilla Bugzilla, Mozilla Security Advisories, and SecurityFocus websites.