Related Vulnerabilities: CVE-2018-5153  

An information disclosure vulnerability has been found in Firefox < 60.0. If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bounds read with the read memory sent to the originating server in response.

Severity Medium

Remote Yes

Type Information disclosure

Description

An information disclosure vulnerability has been found in Firefox < 60.0. If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bounds read with the read memory sent to the originating server in response.

AVG-693 firefox 59.0.2-3 60.0-1 Critical Fixed

13 May 2018 ASA-201805-10 AVG-693 firefox Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/#CVE-2018-5153
https://bugzilla.mozilla.org/show_bug.cgi?id=1436809