The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefox-esr | Apr 5, 2018 | Mar 21, 2018 |
| Debian | — | Upgrade firefox-esrUpgrade libvorbisidec | Feb 19, 2019 | Jun 11, 2018 |
| Freebsd | — | Upgrade firefoxUpgrade libtremorUpgrade waterfoxUpgrade seamonkeyUpgrade libxulUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade linux-firefoxUpgrade libvorbisUpgrade firefox-esrUpgrade linux-thunderbird | Dec 10, 2025 | Mar 16, 2018 |
| Mfsa2018 08 | — | Upgrade to Mozilla Firefox version 59.0.1Upgrade to Mozilla Firefox ESR version 52.7.2 | Mar 19, 2018 | Mar 16, 2018 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations | Jun 21, 2018 | Mar 29, 2018 |
| Ubuntu | — | Upgrade libvorbisidecUpgrade firefox | Nov 19, 2024 | Jun 11, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub