CVE-2018-5183
published 2018-06-11CVE-2018-5183: Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes…
PriorityP338critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.18%
86.6th percentile
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox-esr | < firefox-esr 52.8.0esr-1 (bookworm) | firefox-esr 52.8.0esr-1 (bookworm) |
| debian | thunderbird | < firefox-esr 52.8.0esr-1 (bookworm) | firefox-esr 52.8.0esr-1 (bookworm) |
| mozilla | firefox | < 52.8.0 | 52.8.0 |
| mozilla | firefox_esr | >= unspecified < 52.8 | 52.8 |
| mozilla | thunderbird | < 52.8.0 | 52.8.0 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0-1 | 1:52.8.0-1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0+build1-0ubuntu0.14.04.1 | 1:52.8.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0+build1-0ubuntu0.16.04.1 | 1:52.8.0+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.8.0+build1-0ubuntu0.18.04.1 | 1:52.8.0+build1-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= unspecified < 52.8 | 52.8 |
| mozilla | thunderbird_esr | < 52.8.0 | 52.8.0 |
| mozilla | thunderbird_esr | >= unspecified < 52.8 | 52.8 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-62wp-qw94-ppmq: Mozilla developers backported selected changes in the Skia library
ghsa_unreviewed·2022-05-14
CVE-2018-5183 [CRITICAL] CWE-119 GHSA-62wp-qw94-ppmq: Mozilla developers backported selected changes in the Skia library
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
OSV
CVE-2018-5183: Mozilla developers backported selected changes in the Skia library
osv·2018-06-11·CVSS 9.8
CVE-2018-5183 [CRITICAL] CVE-2018-5183: Mozilla developers backported selected changes in the Skia library
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
OSV
thunderbird vulnerabilities
osv·2018-05-25·CVSS 9.8
CVE-2018-5150 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service
via application crash, install lightweight themes without user
interaction, or execute arbitrary code. (CVE-2018-5150, CVE-2018-5154,
CVE-2018-5155, CVE-2018-5159, CVE-2018-5168, CVE-2018-5178)
An issue was discovered when processing message headers in Thunderbird. If
a user were tricked in to opening a specially crafted message, an attacker
could potentially exploit this to cause a denial of service via
application hang. (CVE-2018-5161)
It was discovered encrypted messages could leak plaintext via the src
attribute of remote images or links. An
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2018-05-25·CVSS 9.8
CVE-2018-5150 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service
via application crash, install lightweight themes without user
interaction, or execute arbitrary code. (CVE-2018-5150, CVE-2018-5154,
CVE-2018-5155, CVE-2018-5159, CVE-2018-5168, CVE-2018-5178)
An issue was discovered when processing message headers in Thunderbird. If
a user were tricked in to opening a specially crafted message, an attacker
could potentially exploit this to cause a denial of service via
application hang. (CVE-2018-5161)
It was discovered encrypted messages coul
Red Hat
Mozilla: Backport critical security fixes in Skia
vendor_redhat·2018-05-09·CVSS 9.8
CVE-2018-5183 [CRITICAL] CWE-120 Mozilla: Backport critical security fixes in Skia
Mozilla: Backport critical security fixes in Skia
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-5183: firefox-esr - Mozilla developers backported selected changes in the Skia library. These change...
vendor_debian·2018·CVSS 9.8
CVE-2018-5183 [CRITICAL] CVE-2018-5183: firefox-esr - Mozilla developers backported selected changes in the Skia library. These change...
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
Scope: local
bookworm: resolved (fixed in 52.8.0esr-1)
bullseye: resolved (fixed in 52.8.0esr-1)
forky: resolved (fixed in 52.8.0esr-1)
sid: resolved (fixed in 52.8.0esr-1)
trixie: resolved (fixed in 52.8.0esr-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5183 Mozilla: Backport critical security fixes in Skia
bugzilla·2018-05-09·CVSS 9.8
CVE-2018-5183 [CRITICAL] CVE-2018-5183 Mozilla: Backport critical security fixes in Skia
CVE-2018-5183 Mozilla: Backport critical security fixes in Skia
Mozilla developers backported selected changes in the Skia library to the ESR52 branch of Firefox. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5183
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Mozilla Developers
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://access.redhat.com/errata/RHSA-2018:1415
---
This issu
Bugzilla
CVE-2015-5183 Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ
bugzilla·2015-07-31·CVSS 7.5
CVE-2015-5183 [HIGH] CVE-2015-5183 Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ
CVE-2015-5183 Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ
It was found that A-MQ's Hawtio console does not set HTTPOnly or Secure attributes on cookies. An attacker could use this flaw to rerieve an authenticated user's SessionID, and possibly conduct further attacks with the permissions of the authenticated user.
Discussion:
Acknowledgements:
Red Hat would like to thank Naftali Rosenbaum of Comsec Consulting for reporting this issue.
---
Is there any plans to resolve this issue?
---
This issue has been addressed in the following products:
Red Hat JBoss Fuse
Via RHSA-2018:2840 https://access.redhat.com/errata/RHSA-2018:2840
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redh
http://www.securityfocus.com/bid/104138http://www.securitytracker.com/id/1040898https://access.redhat.com/errata/RHSA-2018:1414https://access.redhat.com/errata/RHSA-2018:1415https://access.redhat.com/errata/RHSA-2018:1725https://access.redhat.com/errata/RHSA-2018:1726https://bugzilla.mozilla.org/show_bug.cgi?id=1454692https://lists.debian.org/debian-lts-announce/2018/05/msg00007.htmlhttps://lists.debian.org/debian-lts-announce/2018/05/msg00013.htmlhttps://security.gentoo.org/glsa/201810-01https://security.gentoo.org/glsa/201811-13https://usn.ubuntu.com/3660-1/https://www.debian.org/security/2018/dsa-4199https://www.debian.org/security/2018/dsa-4209https://www.mozilla.org/security/advisories/mfsa2018-12/https://www.mozilla.org/security/advisories/mfsa2018-13/http://www.securityfocus.com/bid/104138http://www.securitytracker.com/id/1040898https://access.redhat.com/errata/RHSA-2018:1414https://access.redhat.com/errata/RHSA-2018:1415https://access.redhat.com/errata/RHSA-2018:1725https://access.redhat.com/errata/RHSA-2018:1726https://bugzilla.mozilla.org/show_bug.cgi?id=1454692https://lists.debian.org/debian-lts-announce/2018/05/msg00007.htmlhttps://lists.debian.org/debian-lts-announce/2018/05/msg00013.htmlhttps://security.gentoo.org/glsa/201810-01https://security.gentoo.org/glsa/201811-13https://usn.ubuntu.com/3660-1/https://www.debian.org/security/2018/dsa-4199https://www.debian.org/security/2018/dsa-4209https://www.mozilla.org/security/advisories/mfsa2018-12/https://www.mozilla.org/security/advisories/mfsa2018-13/
2018-06-11
Published