Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade thunderbirdUpgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade firefoxUpgrade firefox-esrUpgrade libxulUpgrade seamonkeyUpgrade linux-firefox | Sep 29, 2017 | Sep 29, 2017 |
| Mfsa2017 21 | — | Upgrade to Mozilla Firefox version 56.0Upgrade to the latest version of Mozilla Firefox | Jul 12, 2018 | Jun 11, 2018 |
| Oracle Solaris | — | Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 52.2.0-0.175.3.22.0.3.0 on Solaris 11.3Upgrade web/browser/firefox to version 52.2.0-0.175.3.22.0.2.0 on Solaris 11.3Upgrade mail/thunderbird to version 52.2.0-0.175.3.22.0.3.0 on Solaris 11.3Upgrade web/data/firefox-bookmarks to version 52.2.0-0.175.3.22.0.2.0 on Solaris 11.3Upgrade web/browser/firefox/plugin/firefox-java to version 52.2.0-0.175.3.22.0.2.0 on Solaris 11.3 | Aug 24, 2018 | Jun 11, 2018 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translations-common | May 20, 2018 | Sep 28, 2017 |
| Ubuntu | — | Upgrade firefox | Oct 3, 2017 | Sep 28, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub