First published: Wed May 09 2018(Updated: )
A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <52.8 | 52.8 |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Mozilla Firefox ESR | <52.8.0 | |
Mozilla Thunderbird | <52.8.0 | |
Mozilla Thunderbird Esr | <52.8.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Canonical Ubuntu Linux | =18.04 | |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Server Aus | =7.6 | |
Redhat Enterprise Linux Server Eus | =7.5 | |
Redhat Enterprise Linux Server Eus | =7.6 | |
Redhat Enterprise Linux Server Tus | =7.6 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Mozilla Thunderbird | <52.8 | 52.8 |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.3.1esr-1~deb11u1 115.14.0esr-1~deb12u1 128.3.1esr-1~deb12u1 128.3.0esr-2 128.3.1esr-2 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:115.16.0esr-1~deb11u1 1:115.12.0-1~deb12u1 1:115.16.0esr-1~deb12u1 1:128.2.0esr-1 1:128.3.0esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2018-5178 is 8.1 (high).
CVE-2018-5178 affects Thunderbird ESR < 52.8, Thunderbird < 52.8, Mozilla Firefox ESR < 52.8, Mozilla Thunderbird < 52.8, and Debian Debian Linux (versions 7.0, 8.0, and 9.0).
To fix CVE-2018-5178, update your software to Thunderbird ESR 52.8 or later, Thunderbird 52.8 or later, Mozilla Firefox ESR 52.8 or later, or Mozilla Thunderbird 52.8 or later.
Yes, you can find references for CVE-2018-5178 at the following links: https://bugzilla.mozilla.org/show_bug.cgi?id=1443891, https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/, http://www.securityfocus.com/bid/104138.
The Common Weakness Enumeration (CWE) for CVE-2018-5178 is 119.