CVE-2018-5104

unknown
Published — · Modified —
CVSS v3
VIR risk

Description

A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debiansidfixed58.0-1
debian debianbookwormfixed52.6.0esr-1
debian debianbullseyefixed52.6.0esr-1
debian debianforkyfixed52.6.0esr-1
debian debiantrixiefixed52.6.0esr-1

References

💬 Discuss CVE-2018-5104 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.