CVE-2018-5146
published 2018-06-11CVE-2018-5146: The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This…
PriorityP347high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
12.05%
95.7th percentile
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 59.0.1-1 (sid) | firefox 59.0.1-1 (sid) |
| debian | firefox-esr | < firefox 59.0.1-1 (sid) | firefox 59.0.1-1 (sid) |
| debian | libvorbis | < firefox 59.0.1-1 (sid) | firefox 59.0.1-1 (sid) |
| debian | libvorbisidec | < firefox 59.0.1-1 (sid) | firefox 59.0.1-1 (sid) |
| debian | thunderbird | < firefox 59.0.1-1 (sid) | firefox 59.0.1-1 (sid) |
| android | — | — | |
| mozilla | firefox | < 52.7.2 | 52.7.2 |
| mozilla | firefox | < 59.0.1 | 59.0.1 |
| mozilla | firefox | >= 0 < 59.0.1+build1-0ubuntu0.14.04.1 | 59.0.1+build1-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 59.0.1+build1-0ubuntu0.16.04.1 | 59.0.1+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | < 52.7.0 | 52.7.0 |
| mozilla | thunderbird | >= 0 < 1:52.7.0-1 | 1:52.7.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.7.0-1 | 1:52.7.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.7.0-1 | 1:52.7.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.7.0-1 | 1:52.7.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.7.0+build1-0ubuntu0.14.04.1 | 1:52.7.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.7.0+build1-0ubuntu0.16.04.1 | 1:52.7.0+build1-0ubuntu0.16.04.1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is an out-of-bounds memory write triggered while processing maliciously crafted Vorbis audio data (OGG file or audio stream); flag processing of crafted OGG/Vorbis content in Firefox, Thunderbird, or libvorbis-linked applications ↗
- →Attack vector is a specially crafted website delivering malicious Vorbis audio; monitor for exploitation attempts via browser-based audio processing ↗
- →On Android and ARM platforms, Firefox uses libtremor instead of libvorbis; the same flaw exists in libtremor — extend detection coverage to libtremor on those platforms ↗
- →Affected Android AOSP versions are 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1 — prioritize patching/detection on these versions; Android reference ID A-77284393 ↗
- ·Firefox versions below 59.0.1 and Firefox ESR below 52.7.2 are vulnerable; Thunderbird below 52.7 is also affected — use these version thresholds for asset inventory and patch-gap detection ↗
- ·Red Hat notes that xulrunner is limited to local content an attacker cannot control, and esc has no audio support — these components are not impacted and should not generate false-positive alerts ↗
- ·CVE-2020-20412 (lib/codebook.c in libvorbis before 1.3.6) may overlap with CVE-2018-5146; avoid double-counting findings across these two CVEs when triaging ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qxgw-7whg-72j2: An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest
ghsa_unreviewed·2022-05-14
CVE-2018-5146 [HIGH] CWE-787 GHSA-qxgw-7whg-72j2: An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
GHSA
GHSA-mxw3-h8f2-qrw5: The libtremor library has the same flaw as CVE-2018-5146
ghsa_unreviewed·2022-05-14·CVSS 8.8
CVE-2018-5147 [HIGH] CWE-787 GHSA-mxw3-h8f2-qrw5: The libtremor library has the same flaw as CVE-2018-5146
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.
OSV
CVE-2018-5147: The libtremor library has the same flaw as CVE-2018-5146
osv·2018-06-11·CVSS 8.8
CVE-2018-5147 [HIGH] CVE-2018-5147: The libtremor library has the same flaw as CVE-2018-5146
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.
OSV
CVE-2018-5146: An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest
osv·2018-06-11·CVSS 8.8
CVE-2018-5146 [HIGH] CVE-2018-5146: An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
OSV
thunderbird vulnerabilities
osv·2018-03-29·CVSS 8.8
CVE-2018-5125 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
or execute arbitrary code. (CVE-2018-5125, CVE-2018-5127, CVE-2018-5129,
CVE-2018-5144, CVE-2018-5145, CVE-2018-5146)
OSV
firefox vulnerability
osv·2018-03-16·CVSS 8.8
CVE-2018-5146 [HIGH] firefox vulnerability
firefox vulnerability
An out-of-bounds write was discovered when processing Vorbis audio data.
If a user were tricked in to opening a specially crafted website, an
attacker could exploit this to cause a denial of service, or execute
arbitrary code. (CVE-2018-5146)
Android
CVE-2018-5146: Android Security Bulletin 2018-06-01
CVE: CVE-2018-5146
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 6
vendor_android·2018-06-01·CVSS 8.8
CVE-2018-5146 [HIGH] CVE-2018-5146: Android Security Bulletin 2018-06-01
CVE: CVE-2018-5146
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 6
Android Security Bulletin 2018-06-01
CVE: CVE-2018-5146
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1
References: A-77284393*
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2018-03-29·CVSS 8.8
CVE-2018-5125 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
or execute arbitrary code. (CVE-2018-5125, CVE-2018-5127, CVE-2018-5129,
CVE-2018-5144, CVE-2018-5145, CVE-2018-5146)
Instructions: After a standard system update you need to restart Thunderbird to make
all the necessary changes.
Ubuntu
libvorbis vulnerability
vendor_ubuntu·2018-03-22
CVE-2018-5146 libvorbis vulnerability
Title: libvorbis vulnerability
Summary: libvorbis could be made to crash or run programs as your login if it
opened a specially crafted file.
Richard Zhu discovered that libvorbis incorrectly handled certain sound
files. An attacker could use this to cause libvorbis to crash, resulting in
a denial or service, or possibly execute arbitrary code.
Instructions: After a standard system upgrade you need to restart any applications that
use libvorbis, such as Totem and gtkpod, to effect the necessary changes.
Red Hat
Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08)
vendor_redhat·2018-03-16·CVSS 8.8
CVE-2018-5146 [HIGH] CWE-122 Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08)
Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08)
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
An out of bounds write flaw was found in the processing of vorbis audio data. A maliciously crafted file or audio stream could cause the application to crash or, potentially, execute arbitrary code.
Statement: Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
The affected c
Ubuntu
Firefox vulnerability
vendor_ubuntu·2018-03-16·CVSS 8.8
CVE-2018-5146 [HIGH] Firefox vulnerability
Title: Firefox vulnerability
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
An out-of-bounds write was discovered when processing Vorbis audio data.
If a user were tricked in to opening a specially crafted website, an
attacker could exploit this to cause a denial of service, or execute
arbitrary code. (CVE-2018-5146)
Instructions: After a standard system update you need to restart Firefox to make
all the necessary changes.
Debian
CVE-2018-5147: firefox - The libtremor library has the same flaw as CVE-2018-5146. This library is used b...
vendor_debian·2018·CVSS 8.8
CVE-2018-5147 [HIGH] CVE-2018-5147: firefox - The libtremor library has the same flaw as CVE-2018-5146. This library is used b...
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.
Scope: local
sid: resolved (fixed in 59.0.1-1)
Debian
CVE-2018-5146: firefox - An out of bounds memory write while processing Vorbis audio data was reported th...
vendor_debian·2018·CVSS 8.8
CVE-2018-5146 [HIGH] CVE-2018-5146: firefox - An out of bounds memory write while processing Vorbis audio data was reported th...
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
Scope: local
sid: resolved (fixed in 59.0.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5146 mozjs45: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
bugzilla·2018-03-19·CVSS 8.8
CVE-2018-5146 [HIGH] CVE-2018-5146 mozjs45: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
CVE-2018-5146 mozjs45: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2018-5146 mozjs38: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
bugzilla·2018-03-19·CVSS 8.8
CVE-2018-5146 [HIGH] CVE-2018-5146 mozjs38: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
CVE-2018-5146 mozjs38: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2018-5146 thunderbird: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
bugzilla·2018-03-19·CVSS 8.8
CVE-2018-5146 [HIGH] CVE-2018-5146 thunderbird: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
CVE-2018-5146 thunderbird: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2018-5146 mozjs38: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [epel-7]
bugzilla·2018-03-19·CVSS 8.8
CVE-2018-5146 [HIGH] CVE-2018-5146 mozjs38: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [epel-7]
CVE-2018-5146 mozjs38: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following tem
Bugzilla
CVE-2018-5146 mingw-libvorbis: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
bugzilla·2018-03-19·CVSS 8.8
CVE-2018-5146 [HIGH] CVE-2018-5146 mingw-libvorbis: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
CVE-2018-5146 mingw-libvorbis: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2018-5146 libvorbis: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
bugzilla·2018-03-19·CVSS 8.8
CVE-2018-5146 [HIGH] CVE-2018-5146 libvorbis: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
CVE-2018-5146 libvorbis: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2018-5146 mingw-libvorbis: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [epel-7]
bugzilla·2018-03-19·CVSS 8.8
CVE-2018-5146 [HIGH] CVE-2018-5146 mingw-libvorbis: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [epel-7]
CVE-2018-5146 mingw-libvorbis: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the follo
Bugzilla
CVE-2018-5146 xulrunner: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-26]
bugzilla·2018-03-19·CVSS 8.8
CVE-2018-5146 [HIGH] CVE-2018-5146 xulrunner: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-26]
CVE-2018-5146 xulrunner: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) [fedora-26]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-26.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the follo
Bugzilla
CVE-2018-5146 Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08)
bugzilla·2018-03-16·CVSS 8.8
CVE-2018-5146 [HIGH] CVE-2018-5146 Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08)
CVE-2018-5146 Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08)
As per upstream advisory:
An out of bounds write while processing vorbis audio data was reported through the Pwn2Own contest.
Discussion:
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-08
---
This issue is now public via upstream advisory:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-08/
---
*** Bug 1557113 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0549 https://access.redhat.com/errata/RHSA-2018:0549
---
Created mozjs45 tracking bugs for this issue:
Affects: fedora-all [bug 1558176]
Created mozjs38 tracking bugs
http://www.securityfocus.com/bid/103432http://www.securitytracker.com/id/1040544https://bugzilla.mozilla.org/show_bug.cgi?id=1446365https://lists.debian.org/debian-lts-announce/2018/03/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2018/03/msg00022.htmlhttps://www.debian.org/security/2018/dsa-4141https://www.debian.org/security/2018/dsa-4143https://www.mozilla.org/security/advisories/mfsa2018-08/http://www.securityfocus.com/bid/103432http://www.securitytracker.com/id/1040544https://bugzilla.mozilla.org/show_bug.cgi?id=1446365https://lists.debian.org/debian-lts-announce/2018/03/msg00016.htmlhttps://lists.debian.org/debian-lts-announce/2018/03/msg00022.htmlhttps://www.debian.org/security/2018/dsa-4141https://www.debian.org/security/2018/dsa-4143https://www.mozilla.org/security/advisories/mfsa2018-08/
2018-06-11
Published