CLD-386 Details

Other IDs this deficiency may be known by:

CVE ID None
Other ID(s) fixed-in-52.8.0, mfsa2018-12

Basic Information:

Affected Package(s) firefox
Deficiency Type SECURITY
Date Created 2018-05-10 09:32:09
Date Last Modified 2018-05-10 09:44:02

Version Specific Information:

Cucumber 1.0 i686fixed in firefox-52.8.0esr-i686-1
Cucumber 1.0 x86_64fixed in firefox-52.8.0esr-x86_64-1

Cucumber 1.1 i686 fixed in firefox-52.8.0esr-i686-1
Cucumber 1.1 x86_64 fixed in firefox-52.8.0esr-x86_64-1

Details:

Addresses the following CVEs:

CVE-2018-5183: Backport critical security fixes in Skia
CVE-2018-5154: Use-after-free with SVG animations and clip paths
CVE-2018-5155: Use-after-free with SVG animations and text paths
CVE-2018-5157: Same-origin bypass of PDF Viewer to view protected PDF files
CVE-2018-5158: Malicious PDF can inject JavaScript into PDF Viewer
CVE-2018-5159: Integer overflow and out-of-bounds write in Skia
CVE-2018-5168: Lightweight themes can be installed without user interaction
CVE-2018-5174: Windows Defender SmartScreen UI runs with less secure behavior
	for downloaded files in Windows 10 April 2018 Update
CVE-2018-5178: Buffer overflow during UTF-8 to Unicode string conversion
	through legacy extension
CVE-2018-5150: Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8

For more information see:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/