Alpine: multiple firefox-esr packages: security update to 52.6.0-r0

critical Tenable Cloud Security Plugin ID 404414

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A use-after-free vulnerability can occur during font face manipulation when a font face is freed while
still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6,
Firefox ESR < 52.6, and Firefox < 58. (CVE-2018-5104)

- Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of
memory corruption and we presume that with enough effort that some of these could be exploited to run
arbitrary code. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
(CVE-2018-5089)

- A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers.
This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox
< 58. (CVE-2018-5091)

- An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some
systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a
potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and
Firefox < 58. (CVE-2018-5095)

- A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a
potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird < 52.6.
(CVE-2018-5096)

See Also

https://security.alpinelinux.org/vuln/CVE-2018-5089

https://security.alpinelinux.org/vuln/CVE-2018-5091

https://security.alpinelinux.org/vuln/CVE-2018-5095

https://security.alpinelinux.org/vuln/CVE-2018-5096

https://security.alpinelinux.org/vuln/CVE-2018-5097

https://security.alpinelinux.org/vuln/CVE-2018-5098

https://security.alpinelinux.org/vuln/CVE-2018-5099

https://security.alpinelinux.org/vuln/CVE-2018-5102

https://security.alpinelinux.org/vuln/CVE-2018-5103

https://security.alpinelinux.org/vuln/CVE-2018-5104

https://security.alpinelinux.org/vuln/CVE-2018-5117

Plugin Details

Severity: Critical

ID: 404414

Version: Revision 1.30

Type: Local

Published: 10/31/2023

Updated: 1/14/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2018-5104

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 1/23/2018

Reference Information

CVE: CVE-2018-5089, CVE-2018-5091, CVE-2018-5095, CVE-2018-5096, CVE-2018-5097, CVE-2018-5098, CVE-2018-5099, CVE-2018-5102, CVE-2018-5103, CVE-2018-5104, CVE-2018-5117

BID: 102771, 102783