CVE-2018-5148
published 2018-06-11CVE-2018-5148: A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one…
PriorityP340critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.01%
85.9th percentile
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 59.0.2-1 (sid) | firefox 59.0.2-1 (sid) |
| debian | firefox-esr | < firefox 59.0.2-1 (sid) | firefox 59.0.2-1 (sid) |
| mozilla | firefox | < 59.0.2 | 59.0.2 |
| mozilla | firefox | < 52.7.3 | 52.7.3 |
| mozilla | firefox | >= unspecified < 59.0.2 | 59.0.2 |
| mozilla | firefox_esr | >= unspecified < 52.7.3 | 52.7.3 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerability
vendor_ubuntu·2018-03-27
CVE-2018-5148 Firefox vulnerability
Title: Firefox vulnerability
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
A use-after-free was discovered in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service or execute arbitrary code.
Instructions: After a standard system update you need to restart Firefox to make
all the necessary changes.
Red Hat
firefox: Use-after-free in compositor potentially allows code execution
vendor_redhat·2018-03-26·CVSS 9.8
CVE-2018-5148 [CRITICAL] CWE-416 firefox: Use-after-free in compositor potentially allows code execution
firefox: Use-after-free in compositor potentially allows code execution
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.
Statement: Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Package: firefox (Red Hat Enterprise Linux 5) - Will not fix
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-5148: firefox - A use-after-free vulnerability can occur in the compositor during certain graphi...
vendor_debian·2018·CVSS 9.8
CVE-2018-5148 [CRITICAL] CVE-2018-5148: firefox - A use-after-free vulnerability can occur in the compositor during certain graphi...
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.
Scope: local
sid: resolved (fixed in 59.0.2-1)
GHSA
GHSA-x8jx-j549-3mc7: A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counte
ghsa_unreviewed·2022-05-14
CVE-2018-5148 [CRITICAL] CWE-416 GHSA-x8jx-j549-3mc7: A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counte
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.
OSV
CVE-2018-5148: A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counte
osv·2018-06-11·CVSS 9.8
CVE-2018-5148 [CRITICAL] CVE-2018-5148: A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counte
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.
No detection rules found.
No public exploits indexed.
arXiv
Retrofitting Fine Grain Isolation in the Firefox Renderer (Extended Version)
arxiv_fulltext·2020-03-10
Retrofitting Fine Grain Isolation in the Firefox Renderer (Extended Version)
-2em
Retrofitting Fine Grain Isolation in the Firefox Renderer\ Version -1em
Retrofitting Fine Grain Isolation in the Firefox Renderer-1.2em
^
^
^
^
Shravan Narayan
Craig Disselkoen
Tal Garfinkel
Nathan Froyd
Eric Rahm
Sorin Lerner
Hovav Shacham^ ,
Deian Stefan
UC San Diego
Stanford
Mozilla
UT Austin
## Abstract
and other major browsers rely on dozens of third-party libraries to
render audio, video, images, and other content. These libraries are a
frequent source of vulnerabilities. To mitigate this threat, we
are migrating to an architecture that isolates these libraries in
lightweight sandboxes, dramatically reducing the impact of a compromise.
Retrofitting isolation can be labor-intensive, very prone to security bugs, and
requires critical attention to performance. To hel
Bugzilla
CVE-2018-5148 firefox: Use-after-free in compositor potentially allows code execution [fedora-all]
bugzilla·2018-03-27·CVSS 9.8
CVE-2018-5148 [CRITICAL] CVE-2018-5148 firefox: Use-after-free in compositor potentially allows code execution [fedora-all]
CVE-2018-5148 firefox: Use-after-free in compositor potentially allows code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multip
Bugzilla
CVE-2018-5148 firefox: Use-after-free in compositor potentially allows code execution
bugzilla·2018-03-27·CVSS 9.8
CVE-2018-5148 [CRITICAL] CVE-2018-5148 firefox: Use-after-free in compositor potentially allows code execution
CVE-2018-5148 firefox: Use-after-free in compositor potentially allows code execution
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash.
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-10/
Discussion:
Created firefox tracking bugs for this issue:
Affects: fedora-all [bug 1560930]
---
Statement:
Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
http://www.securityfocus.com/bid/103506http://www.securitytracker.com/id/1040574https://access.redhat.com/errata/RHSA-2018:1098https://access.redhat.com/errata/RHSA-2018:1099https://bugzilla.mozilla.org/show_bug.cgi?id=1440717https://lists.debian.org/debian-lts-announce/2018/03/msg00023.htmlhttps://usn.ubuntu.com/3609-1/https://www.debian.org/security/2018/dsa-4153https://www.mozilla.org/security/advisories/mfsa2018-10/http://www.securityfocus.com/bid/103506http://www.securitytracker.com/id/1040574https://access.redhat.com/errata/RHSA-2018:1098https://access.redhat.com/errata/RHSA-2018:1099https://bugzilla.mozilla.org/show_bug.cgi?id=1440717https://lists.debian.org/debian-lts-announce/2018/03/msg00023.htmlhttps://usn.ubuntu.com/3609-1/https://www.debian.org/security/2018/dsa-4153https://www.mozilla.org/security/advisories/mfsa2018-10/
2018-06-11
Published