HTTP: Mozilla Firefox WebAssembly Table Integer Underflow

An integer underflow vulnerability has been reported in WebAssembly components of Mozilla Firefox. Successful exploitation of the vulnerabilities could lead to remote code execution.

Extended Description

A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 58.

Affected Products

Mozilla firefox

Short Name
HTTP:STC:SCRIPT:FIREFOX-INT-UF
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2018-5093 Firefox Integer Mozilla Table Underflow WebAssembly
Release Date
03/13/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Mozilla

Canonical

CVSS Score

5.0

Found a potential security threat?