cbcvebase.
CVE-2018-5146
published 2018-06-11

CVE-2018-5146: The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianfirefox< firefox 59.0.1-1 (sid)firefox 59.0.1-1 (sid)
debianfirefox-esr< firefox 59.0.1-1 (sid)firefox 59.0.1-1 (sid)
debianlibvorbis< firefox 59.0.1-1 (sid)firefox 59.0.1-1 (sid)
debianlibvorbisidec< firefox 59.0.1-1 (sid)firefox 59.0.1-1 (sid)
debianthunderbird< firefox 59.0.1-1 (sid)firefox 59.0.1-1 (sid)
googleandroid
mozillafirefox< 52.7.252.7.2
mozillafirefox< 59.0.159.0.1
mozillafirefox>= 0 < 59.0.1+build1-0ubuntu0.14.04.159.0.1+build1-0ubuntu0.14.04.1
mozillafirefox>= 0 < 59.0.1+build1-0ubuntu0.16.04.159.0.1+build1-0ubuntu0.16.04.1
mozillathunderbird< 52.7.052.7.0
mozillathunderbird>= 0 < 1:52.7.0-11:52.7.0-1
mozillathunderbird>= 0 < 1:52.7.0-11:52.7.0-1
mozillathunderbird>= 0 < 1:52.7.0-11:52.7.0-1
mozillathunderbird>= 0 < 1:52.7.0-11:52.7.0-1
mozillathunderbird>= 0 < 1:52.7.0+build1-0ubuntu0.14.04.11:52.7.0+build1-0ubuntu0.14.04.1
mozillathunderbird>= 0 < 1:52.7.0+build1-0ubuntu0.16.04.11:52.7.0+build1-0ubuntu0.16.04.1
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv8.8HIGH