UBUNTU-CVE-2018-5147

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2018-5147
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-5147.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-5147
Related
Published
2018-06-11T21:29:00Z
Modified
2018-06-11T21:29:00Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.

References

Affected packages

Ubuntu:14.04:LTS / libvorbisidec

Package

Name
libvorbisidec
Purl
pkg:deb/ubuntu/libvorbisidec@1.0.2+svn18153-0.2+deb7u1build0.14.04.1?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.2+svn18153-0.2+deb7u1build0.14.04.1

Affected versions

1.*

1.0.2+svn18153-0.2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "libvorbisidec1": "1.0.2+svn18153-0.2+deb7u1build0.14.04.1",
            "libvorbisidec-dev": "1.0.2+svn18153-0.2+deb7u1build0.14.04.1"
        }
    ]
}

Ubuntu:16.04:LTS / firefox

Package

Name
firefox
Purl
pkg:deb/ubuntu/firefox@59.0.1+build1-0ubuntu0.16.04.1?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
59.0.1+build1-0ubuntu0.16.04.1

Affected versions

41.*

41.0.2+build2-0ubuntu1

42.*

42.0+build2-0ubuntu1

44.*

44.0+build3-0ubuntu2
44.0.1+build1-0ubuntu1
44.0.2+build1-0ubuntu1

45.*

45.0+build2-0ubuntu1
45.0.1+build1-0ubuntu1
45.0.2+build1-0ubuntu1

46.*

46.0+build5-0ubuntu0.16.04.2
46.0.1+build1-0ubuntu0.16.04.2

47.*

47.0+build3-0ubuntu0.16.04.1

48.*

48.0+build2-0ubuntu0.16.04.1

49.*

49.0+build4-0ubuntu0.16.04.1
49.0.2+build2-0ubuntu0.16.04.2

50.*

50.0+build2-0ubuntu0.16.04.2
50.0.2+build1-0ubuntu0.16.04.1
50.1.0+build2-0ubuntu0.16.04.1

51.*

51.0.1+build2-0ubuntu0.16.04.1
51.0.1+build2-0ubuntu0.16.04.2

52.*

52.0+build2-0ubuntu0.16.04.1
52.0.1+build2-0ubuntu0.16.04.1
52.0.2+build1-0ubuntu0.16.04.1

53.*

53.0+build6-0ubuntu0.16.04.1
53.0.2+build1-0ubuntu0.16.04.2
53.0.3+build1-0ubuntu0.16.04.2

54.*

54.0+build3-0ubuntu0.16.04.1

55.*

55.0.1+build2-0ubuntu0.16.04.2
55.0.2+build1-0ubuntu0.16.04.1

56.*

56.0+build6-0ubuntu0.16.04.1
56.0+build6-0ubuntu0.16.04.2

57.*

57.0+build4-0ubuntu0.16.04.5
57.0+build4-0ubuntu0.16.04.6
57.0.1+build2-0ubuntu0.16.04.1
57.0.3+build1-0ubuntu0.16.04.1
57.0.4+build1-0ubuntu0.16.04.1

58.*

58.0+build6-0ubuntu0.16.04.1
58.0.1+build1-0ubuntu0.16.04.1
58.0.2+build1-0ubuntu0.16.04.1

59.*

59.0+build5-0ubuntu0.16.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "firefox-locale-de": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-nl": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-kn": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-gl": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-fy": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-eo": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-km": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-or": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-az": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-lt": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-hy": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-kk": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-sv": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-uk": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-sr": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ca": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-is": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-dbg": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-testsuite": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ne": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ga": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-it": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ja": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-lg": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ms": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-dev": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ia": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ko": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-hr": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-mai": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-nb": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-mozsymbols": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-vi": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-zh-hans": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-he": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-sw": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-el": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-oc": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-xh": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-nn": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ar": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-csb": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-cs": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-gn": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-hsb": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-zu": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-my": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ro": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-globalmenu": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-nso": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-af": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-sk": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-si": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-cy": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-dbgsym": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-cak": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-sq": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-en": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-tr": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-br": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-et": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ast": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-th": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-da": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-fi": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ku": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-fa": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-mn": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ru": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-mk": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-bg": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-hu": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-gu": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-bn": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-kab": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ml": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-an": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-be": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-eu": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-fr": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-pa": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-as": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-lv": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-mr": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-bs": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-te": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-id": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ka": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ta": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-gd": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-zh-hant": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-uz": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-hi": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-es": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-sl": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-pl": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-pt": "59.0.1+build1-0ubuntu0.16.04.1",
            "firefox-locale-ur": "59.0.1+build1-0ubuntu0.16.04.1"
        }
    ]
}

Ubuntu:16.04:LTS / libvorbisidec

Package

Name
libvorbisidec
Purl
pkg:deb/ubuntu/libvorbisidec@1.0.2+svn18153-0.2+deb7u1build0.16.04.1?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.2+svn18153-0.2+deb7u1build0.16.04.1

Affected versions

1.*

1.0.2+svn18153-0.2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "libvorbisidec1": "1.0.2+svn18153-0.2+deb7u1build0.16.04.1",
            "libvorbisidec-dev": "1.0.2+svn18153-0.2+deb7u1build0.16.04.1"
        }
    ]
}

Ubuntu:18.04:LTS / firefox

Package

Name
firefox
Purl
pkg:deb/ubuntu/firefox@59.0.1+build1-0ubuntu1?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
59.0.1+build1-0ubuntu1

Affected versions

56.*

56.0+build6-0ubuntu1

57.*

57.0.1+build2-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "firefox-locale-de": "59.0.1+build1-0ubuntu1",
            "firefox-locale-nl": "59.0.1+build1-0ubuntu1",
            "firefox-locale-kn": "59.0.1+build1-0ubuntu1",
            "firefox-locale-gl": "59.0.1+build1-0ubuntu1",
            "firefox-locale-fy": "59.0.1+build1-0ubuntu1",
            "firefox-locale-eo": "59.0.1+build1-0ubuntu1",
            "firefox-locale-km": "59.0.1+build1-0ubuntu1",
            "firefox-locale-or": "59.0.1+build1-0ubuntu1",
            "firefox-locale-az": "59.0.1+build1-0ubuntu1",
            "firefox-locale-lt": "59.0.1+build1-0ubuntu1",
            "firefox-locale-hy": "59.0.1+build1-0ubuntu1",
            "firefox-locale-kk": "59.0.1+build1-0ubuntu1",
            "firefox-locale-sv": "59.0.1+build1-0ubuntu1",
            "firefox-locale-uk": "59.0.1+build1-0ubuntu1",
            "firefox-locale-sr": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ca": "59.0.1+build1-0ubuntu1",
            "firefox-locale-is": "59.0.1+build1-0ubuntu1",
            "firefox-dbg": "59.0.1+build1-0ubuntu1",
            "firefox-testsuite": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ne": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ga": "59.0.1+build1-0ubuntu1",
            "firefox-locale-it": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ja": "59.0.1+build1-0ubuntu1",
            "firefox-locale-lg": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ms": "59.0.1+build1-0ubuntu1",
            "firefox-dev": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ia": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ko": "59.0.1+build1-0ubuntu1",
            "firefox-locale-hr": "59.0.1+build1-0ubuntu1",
            "firefox-locale-mai": "59.0.1+build1-0ubuntu1",
            "firefox-locale-nb": "59.0.1+build1-0ubuntu1",
            "firefox-mozsymbols": "59.0.1+build1-0ubuntu1",
            "firefox-locale-vi": "59.0.1+build1-0ubuntu1",
            "firefox-locale-zh-hans": "59.0.1+build1-0ubuntu1",
            "firefox-locale-he": "59.0.1+build1-0ubuntu1",
            "firefox-locale-sw": "59.0.1+build1-0ubuntu1",
            "firefox-locale-el": "59.0.1+build1-0ubuntu1",
            "firefox-locale-oc": "59.0.1+build1-0ubuntu1",
            "firefox-locale-xh": "59.0.1+build1-0ubuntu1",
            "firefox-locale-nn": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ar": "59.0.1+build1-0ubuntu1",
            "firefox-locale-csb": "59.0.1+build1-0ubuntu1",
            "firefox-locale-cs": "59.0.1+build1-0ubuntu1",
            "firefox-locale-gn": "59.0.1+build1-0ubuntu1",
            "firefox-locale-hsb": "59.0.1+build1-0ubuntu1",
            "firefox-locale-zu": "59.0.1+build1-0ubuntu1",
            "firefox-locale-my": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ro": "59.0.1+build1-0ubuntu1",
            "firefox-globalmenu": "59.0.1+build1-0ubuntu1",
            "firefox-locale-nso": "59.0.1+build1-0ubuntu1",
            "firefox-locale-af": "59.0.1+build1-0ubuntu1",
            "firefox-locale-sk": "59.0.1+build1-0ubuntu1",
            "firefox-locale-si": "59.0.1+build1-0ubuntu1",
            "firefox": "59.0.1+build1-0ubuntu1",
            "firefox-locale-cy": "59.0.1+build1-0ubuntu1",
            "firefox-locale-fa": "59.0.1+build1-0ubuntu1",
            "firefox-locale-cak": "59.0.1+build1-0ubuntu1",
            "firefox-locale-sq": "59.0.1+build1-0ubuntu1",
            "firefox-locale-en": "59.0.1+build1-0ubuntu1",
            "firefox-locale-tr": "59.0.1+build1-0ubuntu1",
            "firefox-locale-br": "59.0.1+build1-0ubuntu1",
            "firefox-locale-et": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ast": "59.0.1+build1-0ubuntu1",
            "firefox-locale-th": "59.0.1+build1-0ubuntu1",
            "firefox-locale-da": "59.0.1+build1-0ubuntu1",
            "firefox-locale-fi": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ku": "59.0.1+build1-0ubuntu1",
            "firefox-locale-mn": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ru": "59.0.1+build1-0ubuntu1",
            "firefox-locale-mk": "59.0.1+build1-0ubuntu1",
            "firefox-locale-bg": "59.0.1+build1-0ubuntu1",
            "firefox-locale-hu": "59.0.1+build1-0ubuntu1",
            "firefox-locale-gu": "59.0.1+build1-0ubuntu1",
            "firefox-locale-bn": "59.0.1+build1-0ubuntu1",
            "firefox-locale-kab": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ml": "59.0.1+build1-0ubuntu1",
            "firefox-locale-an": "59.0.1+build1-0ubuntu1",
            "firefox-locale-be": "59.0.1+build1-0ubuntu1",
            "firefox-locale-eu": "59.0.1+build1-0ubuntu1",
            "firefox-locale-fr": "59.0.1+build1-0ubuntu1",
            "firefox-locale-pa": "59.0.1+build1-0ubuntu1",
            "firefox-locale-as": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ta": "59.0.1+build1-0ubuntu1",
            "firefox-locale-mr": "59.0.1+build1-0ubuntu1",
            "firefox-locale-gd": "59.0.1+build1-0ubuntu1",
            "firefox-locale-te": "59.0.1+build1-0ubuntu1",
            "firefox-locale-id": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ka": "59.0.1+build1-0ubuntu1",
            "firefox-locale-lv": "59.0.1+build1-0ubuntu1",
            "firefox-locale-bs": "59.0.1+build1-0ubuntu1",
            "firefox-locale-zh-hant": "59.0.1+build1-0ubuntu1",
            "firefox-locale-uz": "59.0.1+build1-0ubuntu1",
            "firefox-locale-hi": "59.0.1+build1-0ubuntu1",
            "firefox-locale-es": "59.0.1+build1-0ubuntu1",
            "firefox-locale-sl": "59.0.1+build1-0ubuntu1",
            "firefox-locale-pl": "59.0.1+build1-0ubuntu1",
            "firefox-locale-pt": "59.0.1+build1-0ubuntu1",
            "firefox-locale-ur": "59.0.1+build1-0ubuntu1"
        }
    ]
}

Ubuntu:18.04:LTS / libvorbisidec

Package

Name
libvorbisidec
Purl
pkg:deb/ubuntu/libvorbisidec@1.0.2+svn18153-1+deb9u1?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.2+svn18153-1+deb9u1

Affected versions

1.*

1.0.2+svn18153-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "libvorbisidec1-dbgsym": "1.0.2+svn18153-1+deb9u1",
            "libvorbisidec1": "1.0.2+svn18153-1+deb9u1",
            "libvorbisidec-dev": "1.0.2+svn18153-1+deb9u1"
        }
    ]
}