Mozilla Firefox ESR Remote Memory Corruption and Buffer Overflow Vulnerabilities
BID:104138
CVE-2018-5178 | CVE-2018-5183 |Info
Mozilla Firefox ESR Remote Memory Corruption and Buffer Overflow Vulnerabilities
| Bugtraq ID: | 104138 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2018-5178 CVE-2018-5183 |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2018 12:00AM |
| Updated: | May 09 2018 12:00AM |
| Credit: | Root Object, and Mozilla developers. |
| Vulnerable: |
Mozilla Firefox ESR 52.7.3 Mozilla Firefox ESR 52.7.2 Mozilla Firefox ESR 52.1.1 Mozilla Firefox ESR 45.5.1 Mozilla Firefox ESR 38.6.1 Mozilla Firefox ESR 38.5.2 Mozilla Firefox ESR 38.5.1 Mozilla Firefox ESR 38.1.1 Mozilla Firefox ESR 31.5.3 Mozilla Firefox ESR 24.1 Mozilla Firefox ESR 24.0.1 Mozilla Firefox ESR 17.0.10 Mozilla Firefox ESR 17.0.9 Mozilla Firefox ESR 17.0.7 Mozilla Firefox ESR 17.0.6 Mozilla Firefox ESR 17.0.5 Mozilla Firefox ESR 17.0.4 Mozilla Firefox ESR 17.0.3 Mozilla Firefox ESR 17.0.2 Mozilla Firefox ESR 17.0.1 Mozilla Firefox ESR 10.0.12 Mozilla Firefox ESR 10.0.10 Mozilla Firefox ESR 10.0.8 Mozilla Firefox ESR 10.0.7 Mozilla Firefox ESR 10.0.5 Mozilla Firefox ESR 10.0.4 Mozilla Firefox ESR 10.0.3 Mozilla Firefox ESR 52.7 Mozilla Firefox ESR 52.6 Mozilla Firefox ESR 52.5.2 Mozilla Firefox ESR 52.5 Mozilla Firefox ESR 52.4 Mozilla Firefox ESR 52.3 Mozilla Firefox ESR 52.2 Mozilla Firefox ESR 52.1 Mozilla Firefox ESR 52.0.1 Mozilla Firefox ESR 45.9 Mozilla Firefox ESR 45.8 Mozilla Firefox ESR 45.7 Mozilla Firefox ESR 45.6 Mozilla Firefox ESR 45.5 Mozilla Firefox ESR 45.4 Mozilla Firefox ESR 45.3 Mozilla Firefox ESR 45.2 Mozilla Firefox ESR 45.1 Mozilla Firefox ESR 38.8 Mozilla Firefox ESR 38.7 Mozilla Firefox ESR 38.6 Mozilla Firefox ESR 38.5 Mozilla Firefox ESR 38.4 Mozilla Firefox ESR 38.3 Mozilla Firefox ESR 38.2.1 Mozilla Firefox ESR 38.2 Mozilla Firefox ESR 38.1 Mozilla Firefox ESR 31.8 Mozilla Firefox ESR 31.7 Mozilla Firefox ESR 31.6 Mozilla Firefox ESR 31.5.2 Mozilla Firefox ESR 31.5 Mozilla Firefox ESR 31.4 Mozilla Firefox ESR 31.3.0 Mozilla Firefox ESR 31.3 Mozilla Firefox ESR 31.2 Mozilla Firefox ESR 31.1.1 Mozilla Firefox ESR 31.1.0 Mozilla Firefox ESR 31.1 Mozilla Firefox ESR 31.0 Mozilla Firefox ESR 24.8.1 Mozilla Firefox ESR 24.8 Mozilla Firefox ESR 24.7 Mozilla Firefox ESR 24.6 Mozilla Firefox ESR 24.5 Mozilla Firefox ESR 24.4 Mozilla Firefox ESR 24.3 Mozilla Firefox ESR 24.2 Mozilla Firefox ESR 24.1.1 Mozilla Firefox ESR 24.1 Mozilla Firefox ESR 24.0.2 Mozilla Firefox ESR 24.0 Mozilla Firefox ESR 17.0.8 Mozilla Firefox ESR 17.0.11 Mozilla Firefox ESR 17.0 Mozilla Firefox ESR 10.0.9 Mozilla Firefox ESR 10.0.6 Mozilla Firefox ESR 10.0.2 Mozilla Firefox ESR 10.0.11 Mozilla Firefox ESR 10.0.1 |
| Not Vulnerable: |
Mozilla Firefox ESR 52.8 |
Discussion
Mozilla Firefox ESR Remote Memory Corruption and Buffer Overflow Vulnerabilities
Mozilla Firefox ESR is prone to a remote memory-corruption vulnerability and a buffer-overflow vulnerability.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
These issues are fixed in:
Firefox ESR 52.8
Mozilla Firefox ESR is prone to a remote memory-corruption vulnerability and a buffer-overflow vulnerability.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
These issues are fixed in:
Firefox ESR 52.8
Exploit / POC
Mozilla Firefox ESR Remote Memory Corruption and Buffer Overflow Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Mozilla Firefox ESR Remote Memory Corruption and Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Mozilla Firefox ESR Remote Memory Corruption and Buffer Overflow Vulnerabilities
References:
References: