HTTP: Mozilla Firefox Vorbis Audio Out of Bounds Write

This signature detects attempts to exploit a known vulnerability against Mozilla Firefox. A successful attack can lead to arbitrary code execution.

Extended Description

An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.

Affected Products

Mozilla firefox_esr

References

BugTraq: 103432

CVE: CVE-2018-5146

Short Name
HTTP:STC:MOZILLA:CVE-2018-5146
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Audio Bounds CVE-2018-5146 Firefox Mozilla Out Vorbis Write bid:103432 of
Release Date
04/07/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Mozilla

Debian

Redhat

Canonical

CVSS Score

6.8

Found a potential security threat?