A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
                
            References
                    Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Configuration 2 (hide)
                                
                                
  | 
                        
Configuration 3 (hide)
                                
                                
  | 
                        
Configuration 4 (hide)
                                
                                
  | 
                        
Configuration 5 (hide)
                                
                                
  | 
                        
Configuration 6 (hide)
                                
                                
  | 
                        
Information
                Published : 2018-06-11 14:29
Updated : 2019-03-08 06:22
NVD link : CVE-2018-5129
Mitre link : CVE-2018-5129
JSON object : View
CWE
                
                    
                        
                        CWE-787
                        
            Out-of-bounds Write
Products Affected
                redhat
- enterprise_linux_desktop
 - enterprise_linux_server_aus
 - enterprise_linux_workstation
 - enterprise_linux_server_eus
 - enterprise_linux_server
 
mozilla
- firefox_esr
 - thunderbird
 - firefox
 
canonical
- ubuntu_linux
 
debian
- debian_linux
 


