The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefox-esr | Apr 5, 2018 | Mar 21, 2018 |
| Debian | — | Upgrade firefox-esrUpgrade libvorbisidec | Feb 19, 2019 | Jun 11, 2018 |
| Freebsd | — | Upgrade linux-thunderbirdUpgrade firefox-esrUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade linux-firefoxUpgrade libvorbisUpgrade libtremorUpgrade libxulUpgrade waterfoxUpgrade firefoxUpgrade seamonkey | Dec 10, 2025 | Mar 16, 2018 |
| Mfsa2018 08 | — | Upgrade to Mozilla Firefox ESR version 52.7.2Upgrade to Mozilla Firefox version 59.0.1 | Mar 19, 2018 | Mar 16, 2018 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translationsUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-common | Jun 21, 2018 | Mar 29, 2018 |
| Ubuntu | — | Upgrade libvorbisidecUpgrade firefox | Nov 19, 2024 | Jun 11, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub