Bug 1670632 (CVE-2018-18501)

Summary: CVE-2018-18501 Mozilla: Memory safety bugs fixed in Firefox 65 and Firefox ESR 60.5
Product: [Other] Security Response Reporter: Doran Moppert <dmoppert>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: cschalle, gecko-bugs-nobody, jan.public, jhorak, stransky, yozone
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-10 10:46:42 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1668153, 1668154, 1668155, 1668156, 1670636, 1670637, 1670638, 1670639, 1670640    
Bug Blocks: 1668151, 1670486    

Description Doran Moppert 2019-01-29 23:18:42 UTC
Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.


External Reference:

https://www.mozilla.org/en-US/security/advisories/mfsa2019-02/#CVE-2018-18501

Comment 1 Doran Moppert 2019-01-29 23:18:44 UTC
Acknowledgments:

Name: the Mozilla project
Upstream: Alex Gaynor, Christoph Diehl, Steven Crane, Jason Kratzer, Gary Kwong, Christian Holler

Comment 7 errata-xmlrpc 2019-01-30 17:38:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2019:0218 https://access.redhat.com/errata/RHSA-2019:0218

Comment 8 errata-xmlrpc 2019-01-30 17:56:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:0219 https://access.redhat.com/errata/RHSA-2019:0219

Comment 9 errata-xmlrpc 2019-02-04 20:41:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2019:0269 https://access.redhat.com/errata/RHSA-2019:0269

Comment 10 errata-xmlrpc 2019-02-04 20:42:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:0270 https://access.redhat.com/errata/RHSA-2019:0270