CVE-2018-5146

Priority
Description
An out of bounds memory write while processing Vorbis audio data was
reported through the Pwn2Own contest. This vulnerability affects Firefox <
59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
Notes
Package
Upstream:released (59.0.1)
Ubuntu 18.04 LTS:not-affected
Ubuntu 16.04 ESM:released (59.0.1+build1-0ubuntu0.16.04.1)
Ubuntu 14.04 ESM:DNE (trusty was released [59.0.1+build1-0ubuntu0.14.04.1])
Patches:
Package
Upstream:released (52.7.2)
Ubuntu 18.04 LTS:DNE
Ubuntu 14.04 ESM:DNE
Patches:
Package
Upstream:needs-triage
Ubuntu 18.04 LTS:not-affected (1.3.5-4.2)
Ubuntu 16.04 ESM:released (1.3.5-3ubuntu0.2)
Ubuntu 14.04 ESM:DNE (trusty was released [1.3.2-1.3ubuntu1.2])
Patches:
Upstream:https://git.xiph.org/?p=vorbis.git;a=commit;h=667ceb4aab60c1f74060143bb24e5f427b3cce5f
Package
Upstream:released (52.7.0)
Ubuntu 18.04 LTS:released (1:52.7.0+build1-0ubuntu1)
Ubuntu 16.04 ESM:released (1:52.7.0+build1-0ubuntu0.16.04.1)
Ubuntu 14.04 ESM:DNE (trusty was released [1:52.7.0+build1-0ubuntu0.14.04.1])
Patches:
More Information

Updated: 2022-04-13 13:32:57 UTC (commit f411bd370d482ef4385c4e751d121a4055fbc009)