First published: Tue Jun 26 2018(Updated: )
Last updated 24 July 2024
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/firefox | 135.0.1-1 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:128.7.0esr-1~deb11u1 1:128.5.0esr-1~deb12u1 1:128.7.0esr-1~deb12u1 1:128.7.0esr-1 | |
Debian | =8.0 | |
Debian | =9.0 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =17.10 | |
Ubuntu | =18.04 | |
Firefox | <61.0 | |
Firefox ESR | <60.1.0 | |
Thunderbird | <60.0 | |
Thunderbird | <60 | 60 |
Firefox | <61 | 61 |
Firefox ESR | <60.1 | 60.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-5187 has a high severity due to its potential to allow arbitrary code execution through memory safety vulnerabilities in affected applications.
To fix CVE-2018-5187, update affected software to the latest version, specifically Thunderbird version 60 or later and Firefox version 61 or later.
CVE-2018-5187 affects Thunderbird versions prior to 60, Firefox ESR versions before 60.1, and Firefox versions prior to 61.
CVE-2018-5187 impacts Mozilla Thunderbird and Mozilla Firefox, specifically versions that are less than the specified fixed versions.
CVE-2018-5187 may be exploited to run arbitrary code due to the identified memory safety bugs if sufficient effort is applied by an attacker.