Unrated severityNVD Advisory· Published Jun 11, 2018· Updated Aug 5, 2024
CVE-2018-5183
CVE-2018-5183
Description
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
Affected products
35- osv-coords32 versionspkg:rpm/suse/MozillaFirefox&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208
< 68.2.0-109.95.2+ 31 more
- (no CPE)range: < 68.2.0-109.95.2
- (no CPE)range: < 52.8.0esr-109.31.2
- (no CPE)range: < 68.2.0-109.95.2
- (no CPE)range: < 52.8.0esr-109.31.2
- (no CPE)range: < 68.2.0-109.95.2
- (no CPE)range: < 52.9.0esr-3.7.12
- (no CPE)range: < 52.8.0esr-72.32.1
- (no CPE)range: < 52.8.0esr-72.32.1
- (no CPE)range: < 52.8.0esr-72.32.1
- (no CPE)range: < 52.8.0esr-72.32.1
- (no CPE)range: < 52.8.0esr-109.31.2
- (no CPE)range: < 52.8.0esr-109.31.2
- (no CPE)range: < 52.8.0esr-109.31.2
- (no CPE)range: < 52.8.0esr-109.31.2
- (no CPE)range: < 68.2.0-109.95.2
- (no CPE)range: < 68.2.0-109.95.2
- (no CPE)range: < 68.2.0-109.95.2
- (no CPE)range: < 68.2.0-109.95.2
- (no CPE)range: < 52.8.0esr-109.31.2
- (no CPE)range: < 52.8.0esr-72.32.1
- (no CPE)range: < 52.8.0esr-109.31.2
- (no CPE)range: < 52.8.0esr-109.31.2
- (no CPE)range: < 52.8.0esr-109.31.2
- (no CPE)range: < 68.2.0-109.95.2
- (no CPE)range: < 68.2.0-109.95.2
- (no CPE)range: < 52.8.0esr-72.32.1
- (no CPE)range: < 52.8.0esr-109.31.2
- (no CPE)range: < 68.2.0-109.95.2
- (no CPE)range: < 68.2.0-109.95.2
- (no CPE)range: < 52.8.0esr-109.31.2
- (no CPE)range: < 68.2.0-109.95.2
- (no CPE)range: < 68.2.0-109.95.2
- Range: unspecified
- Mozilla/Firefox ESRv5Range: unspecified
- Mozilla/Thunderbird ESRv5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
16- access.redhat.com/errata/RHSA-2018:1414mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2018:1415mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2018:1725mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2018:1726mitrevendor-advisoryx_refsource_REDHAT
- security.gentoo.org/glsa/201810-01mitrevendor-advisoryx_refsource_GENTOO
- security.gentoo.org/glsa/201811-13mitrevendor-advisoryx_refsource_GENTOO
- usn.ubuntu.com/3660-1/mitrevendor-advisoryx_refsource_UBUNTU
- www.debian.org/security/2018/dsa-4199mitrevendor-advisoryx_refsource_DEBIAN
- www.debian.org/security/2018/dsa-4209mitrevendor-advisoryx_refsource_DEBIAN
- www.securityfocus.com/bid/104138mitrevdb-entryx_refsource_BID
- www.securitytracker.com/id/1040898mitrevdb-entryx_refsource_SECTRACK
- bugzilla.mozilla.org/show_bug.cgimitrex_refsource_CONFIRM
- lists.debian.org/debian-lts-announce/2018/05/msg00007.htmlmitremailing-listx_refsource_MLIST
- lists.debian.org/debian-lts-announce/2018/05/msg00013.htmlmitremailing-listx_refsource_MLIST
- www.mozilla.org/security/advisories/mfsa2018-12/mitrex_refsource_CONFIRM
- www.mozilla.org/security/advisories/mfsa2018-13/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.