A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefox-debuginfoUpgrade firefox | May 4, 2018 | Mar 27, 2018 |
| Debian | — | Upgrade firefox-esr | Feb 19, 2019 | Jun 11, 2018 |
| Freebsd | — | Upgrade firefox-esrUpgrade firefoxUpgrade linux-thunderbirdUpgrade libxulUpgrade thunderbirdUpgrade linux-firefoxUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade waterfox | Dec 10, 2025 | Mar 27, 2018 |
| Mfsa2018 10 | — | Upgrade to Mozilla Firefox version 59.0.2Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 52.7.3 | Mar 27, 2018 | Mar 26, 2018 |
| Oracle Solaris | — | Upgrade web/browser/firefox/plugin/firefox-java to version 52.7.3-0.175.3.31.0.4.0 on Solaris 11.3Upgrade web/data/firefox-bookmarks to version 52.7.3-0.175.3.31.0.4.0 on Solaris 11.3Upgrade web/browser/firefox to version 52.7.3-0.175.3.31.0.4.0 on Solaris 11.3 | Apr 18, 2018 | Apr 18, 2018 |
| Oracle_linux | — | Upgrade firefox | Mar 2, 2020 | Mar 26, 2018 |
| Redhat_linux | — | Upgrade firefoxNo solution existsUpgrade firefox-debuginfo | May 1, 2018 | Mar 27, 2018 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translationsUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-common | Jun 21, 2018 | Mar 27, 2018 |
| Ubuntu | — | Upgrade firefox | Apr 26, 2018 | Mar 27, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub