CVE-2018-5178: Buffer Overflow
A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-5178?
The severity of CVE-2018-5178 is 8.1 (high).
Which software versions are affected by CVE-2018-5178?
CVE-2018-5178 affects Thunderbird ESR < 52.8, Thunderbird < 52.8, Mozilla Firefox ESR < 52.8, Mozilla Thunderbird < 52.8, and Debian Debian Linux (versions 7.0, 8.0, and 9.0).
How can I fix CVE-2018-5178?
To fix CVE-2018-5178, update your software to Thunderbird ESR 52.8 or later, Thunderbird 52.8 or later, Mozilla Firefox ESR 52.8 or later, or Mozilla Thunderbird 52.8 or later.
Are there any references for CVE-2018-5178?
Yes, you can find references for CVE-2018-5178 at the following links: https://bugzilla.mozilla.org/show_bug.cgi?id=1443891, https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/, http://www.securityfocus.com/bid/104138.
What is the Common Weakness Enumeration (CWE) for CVE-2018-5178?
The Common Weakness Enumeration (CWE) for CVE-2018-5178 is 119.