CVE-2018-5144

Related Vulnerabilities: CVE-2018-5144  

An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.

The MITRE CVE dictionary describes this issue as:

An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.

Find out more about CVE-2018-5144 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 6.1
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality Low
Integrity Impact Low
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 6 (thunderbird) RHSA-2018:0647 2018-04-05
Red Hat Enterprise Linux 7 (thunderbird) RHSA-2018:0648 2018-04-05
Red Hat Enterprise Linux 7 (firefox) RHSA-2018:0527 2018-03-15
Red Hat Enterprise Linux 6 (firefox) RHSA-2018:0526 2018-03-15

Acknowledgements

Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Root Object as the original reporter.

External References