Heap-use-after-free error in Mozilla Firefox - CVE-2018-5180

 

Heap-use-after-free error in Mozilla Firefox - CVE-2018-5180

Published: May 10, 2018


Vulnerability identifier: #VU12532
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5180
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to heap-used-after-free error during WebGL operations. A remote attacker can trick the victim into visiting a specially crafted website, cause the memory to be freed and reused in a brief window of time during the freeing of the same callstack.

Successful exploitation of the vulnerability result may result in system compromise.

Affected software

Mozilla Firefox
Arch Linux

How to mitigate CVE-2018-5180

Update to version 60.0.


External References

Related Security Bulletins