First published: Wed May 09 2018(Updated: )
A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.3.1esr-1~deb11u1 115.14.0esr-1~deb12u1 128.3.1esr-1~deb12u1 128.3.0esr-2 128.3.1esr-2 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:115.16.0esr-1~deb11u1 1:115.12.0-1~deb12u1 1:115.16.0esr-1~deb12u1 1:128.2.0esr-1 1:128.3.0esr-1 | |
Debian | =7.0 | |
Debian | =8.0 | |
Debian | =9.0 | |
Firefox ESR | <52.8.0 | |
Thunderbird | <52.8.0 | |
Mozilla Thunderbird | <52.8.0 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =17.10 | |
Ubuntu | =18.04 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.5 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
Thunderbird | <52.8 | 52.8 |
Firefox ESR | <52.8 | 52.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2018-5178 is 8.1 (high).
CVE-2018-5178 affects Thunderbird ESR < 52.8, Thunderbird < 52.8, Mozilla Firefox ESR < 52.8, Mozilla Thunderbird < 52.8, and Debian Debian Linux (versions 7.0, 8.0, and 9.0).
To fix CVE-2018-5178, update your software to Thunderbird ESR 52.8 or later, Thunderbird 52.8 or later, Mozilla Firefox ESR 52.8 or later, or Mozilla Thunderbird 52.8 or later.
Yes, you can find references for CVE-2018-5178 at the following links: https://bugzilla.mozilla.org/show_bug.cgi?id=1443891, https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/, http://www.securityfocus.com/bid/104138.
The Common Weakness Enumeration (CWE) for CVE-2018-5178 is 119.