cbcvebase.
CVE-2018-5146
published 2018-06-11

CVE-2018-5146: The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This…

PriorityP347high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
12.05%
95.7th percentile
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianfirefox< firefox 59.0.1-1 (sid)firefox 59.0.1-1 (sid)
debianfirefox-esr< firefox 59.0.1-1 (sid)firefox 59.0.1-1 (sid)
debianlibvorbis< firefox 59.0.1-1 (sid)firefox 59.0.1-1 (sid)
debianlibvorbisidec< firefox 59.0.1-1 (sid)firefox 59.0.1-1 (sid)
debianthunderbird< firefox 59.0.1-1 (sid)firefox 59.0.1-1 (sid)
googleandroid
mozillafirefox< 52.7.252.7.2
mozillafirefox< 59.0.159.0.1
mozillafirefox>= 0 < 59.0.1+build1-0ubuntu0.14.04.159.0.1+build1-0ubuntu0.14.04.1
mozillafirefox>= 0 < 59.0.1+build1-0ubuntu0.16.04.159.0.1+build1-0ubuntu0.16.04.1
mozillathunderbird< 52.7.052.7.0
mozillathunderbird>= 0 < 1:52.7.0-11:52.7.0-1
mozillathunderbird>= 0 < 1:52.7.0-11:52.7.0-1
mozillathunderbird>= 0 < 1:52.7.0-11:52.7.0-1
mozillathunderbird>= 0 < 1:52.7.0-11:52.7.0-1
mozillathunderbird>= 0 < 1:52.7.0+build1-0ubuntu0.14.04.11:52.7.0+build1-0ubuntu0.14.04.1
mozillathunderbird>= 0 < 1:52.7.0+build1-0ubuntu0.16.04.11:52.7.0+build1-0ubuntu0.16.04.1
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is an out-of-bounds memory write triggered while processing maliciously crafted Vorbis audio data (OGG file or audio stream); flag processing of crafted OGG/Vorbis content in Firefox, Thunderbird, or libvorbis-linked applications
  • Attack vector is a specially crafted website delivering malicious Vorbis audio; monitor for exploitation attempts via browser-based audio processing
  • On Android and ARM platforms, Firefox uses libtremor instead of libvorbis; the same flaw exists in libtremor — extend detection coverage to libtremor on those platforms
  • Affected Android AOSP versions are 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1 — prioritize patching/detection on these versions; Android reference ID A-77284393
  • ·Firefox versions below 59.0.1 and Firefox ESR below 52.7.2 are vulnerable; Thunderbird below 52.7 is also affected — use these version thresholds for asset inventory and patch-gap detection
  • ·Red Hat notes that xulrunner is limited to local content an attacker cannot control, and esc has no audio support — these components are not impacted and should not generate false-positive alerts
  • ·CVE-2020-20412 (lib/codebook.c in libvorbis before 1.3.6) may overlap with CVE-2018-5146; avoid double-counting findings across these two CVEs when triaging

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.