CVE-2018-5145
Publication date 15 March 2018
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | 24.10 oracular |
Not affected
|
24.04 LTS noble |
Not affected
|
|
22.04 LTS jammy |
Not affected
|
|
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
firefox-esr | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
mozjs38 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Ignored | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
mozjs52 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal |
Vulnerable, fix deferred
|
|
18.04 LTS bionic |
Vulnerable, fix deferred
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
thunderbird | 24.10 oracular |
Fixed 1:52.7.0+build1-0ubuntu1
|
24.04 LTS noble |
Fixed 1:52.7.0+build1-0ubuntu1
|
|
22.04 LTS jammy |
Fixed 1:52.7.0+build1-0ubuntu1
|
|
20.04 LTS focal |
Fixed 1:52.7.0+build1-0ubuntu1
|
|
18.04 LTS bionic |
Fixed 1:52.7.0+build1-0ubuntu1
|
|
16.04 LTS xenial |
Fixed 1:52.7.0+build1-0ubuntu0.16.04.1
|
|
14.04 LTS trusty |
Fixed 1:52.7.0+build1-0ubuntu0.14.04.1
|
Notes
tyhicks
mozjs contains a copy of the SpiderMonkey JavaScript engine
chrisccoulson
It's not clear whether this affects mozjs52, as the bugs are still private and some aren't referenced by any changesets. The following need investigating: - https://bugzilla.mozilla.org/show_bug.cgi?id=1348955
Severity score breakdown
Parameter | Value |
---|---|
Base score | 9.8 · Critical |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-3545-1
- Thunderbird vulnerabilities
- 29 March 2018