CVE-2018-5154: Use After Free
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5183
- CVE-2018-5184
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5159
- CVE-2018-5161
- CVE-2018-5162
- CVE-2018-5170
- CVE-2018-5168
- CVE-2018-5174
- CVE-2018-5178
- CVE-2018-5185
- CVE-2018-5150
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
Frequently Asked Questions
What is CVE-2018-5154?
CVE-2018-5154 is a use-after-free vulnerability that occurs while enumerating attributes during SVG animations with clip paths.
Which software is affected by CVE-2018-5154?
CVE-2018-5154 affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
How severe is CVE-2018-5154?
CVE-2018-5154 has a severity rating of 9.8 (critical).
How do I fix CVE-2018-5154?
To fix CVE-2018-5154, update Thunderbird to version 52.8 or later, or update Firefox to version 60 or later.
Where can I find more information about CVE-2018-5154?
You can find more information about CVE-2018-5154 at the following references: [https://bugzilla.mozilla.org/show_bug.cgi?id=1443092](https://bugzilla.mozilla.org/show_bug.cgi?id=1443092), [https://www.mozilla.org/security/advisories/mfsa2018-11/](https://www.mozilla.org/security/advisories/mfsa2018-11/), [https://www.mozilla.org/security/advisories/mfsa2018-12/](https://www.mozilla.org/security/advisories/mfsa2018-12/).