Related Vulnerabilities: CVE-2018-5154  

A use-after-free vulnerability has been found in Firefox < 60.0 and Thunderbird < 52.8, while enumerating attributes during SVG animations with clip paths.

Severity High

Remote Yes

Type Arbitrary code execution

Description

A use-after-free vulnerability has been found in Firefox < 60.0 and Thunderbird < 52.8, while enumerating attributes during SVG animations with clip paths.

AVG-707 thunderbird 52.7.0-2 52.8.0-1 Critical Fixed

AVG-693 firefox 59.0.2-3 60.0-1 Critical Fixed

21 May 2018 ASA-201805-21 AVG-707 thunderbird Critical multiple issues

13 May 2018 ASA-201805-10 AVG-693 firefox Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/#CVE-2018-5154
https://bugzilla.mozilla.org/show_bug.cgi?id=1443092