7.5
CVSSv2

CVE-2018-5147

Published: 11/06/2018 Updated: 14/08/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 7.0

mozilla firefox esr

mozilla firefox

Vendor Advisories

Debian Bug report logs - #893132 libvorbisidec: CVE-2018-5147: out-of-bounds memory write Package: src:libvorbisidec; Maintainer for src:libvorbisidec is Debian Multimedia Maintainers &lt;debian-multimedia@listsdebianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Fri, 16 Mar 2018 18:33:04 UTC Severi ...
Huzaifa Sidhpurwala discovered that an out-of-bounds memory write in the codebook parsing code of the Libtremor multimedia library could result in the execution of arbitrary code if a malformed Vorbis file is opened For the oldstable distribution (jessie), this problem has been fixed in version 102+svn18153-1~deb8u2 For the stable distribution ...
Richard Zhu and Huzaifa Sidhpurwala discovered that an out-of-bounds memory write when playing Vorbis media files could result in the execution of arbitrary code For the oldstable distribution (jessie), these problems have been fixed in version 5272esr-1~deb8u1 For the stable distribution (stretch), these problems have been fixed in version 52 ...
Mozilla Foundation Security Advisory 2018-08 Out of bounds memory write while processing Vorbis audio data Announced March 16, 2018 Impact critical Products Firefox, Firefox ESR Fixed in Firefox 5901 ...
An out of bounds memory write vulnerability has been discovered in libtremor while processing Vorbis audio data related to codebooks that are not an exact divisor of the partition size ...