#VU11140 Buffer overflow in Mozilla Firefox and Firefox ESR - CVE-2018-5146
Published: March 16, 2018 / Updated: March 16, 2018
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error when processing Vorbis audio within libvorbis library. A remote unauthenticated attacker can create a specially crafted HTML page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.