Heap-use-after-free error in Mozilla Firefox - CVE-2018-5180
Published: May 10, 2018
Vulnerability identifier: #VU12532
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5180
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to heap-used-after-free error during WebGL operations. A remote attacker can trick the victim into visiting a specially crafted website, cause the memory to be freed and reused in a brief window of time during the freeing of the same callstack.
Successful exploitation of the vulnerability result may result in system compromise.
The weakness exists due to heap-used-after-free error during WebGL operations. A remote attacker can trick the victim into visiting a specially crafted website, cause the memory to be freed and reused in a brief window of time during the freeing of the same callstack.
Successful exploitation of the vulnerability result may result in system compromise.
Affected software
Mozilla Firefox
Arch Linux
Arch Linux
How to mitigate CVE-2018-5180
Update to version 60.0.