Alpine: multiple firefox-esr packages: security update to 60.5.0-r0

critical Tenable Cloud Security Plugin ID 404416

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML
elements. This results in the stream parser object being freed while still in use, leading to a
potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and
Firefox < 65. (CVE-2018-18500)

- Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR
60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that
some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5,
Firefox ESR < 60.5, and Firefox < 65. (CVE-2018-18501)

- An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication
to communication between IPC endpoints and server parents during IPC process creation. This authentication
is insufficient for channels created after the IPC process is started, leading to the authentication not
being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due
to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5,
Firefox ESR < 60.5, and Firefox < 65. (CVE-2018-18505)

See Also

https://security.alpinelinux.org/vuln/CVE-2018-18500

https://security.alpinelinux.org/vuln/CVE-2018-18501

https://security.alpinelinux.org/vuln/CVE-2018-18505

Plugin Details

Severity: Critical

ID: 404416

Version: Revision 1.29

Type: Local

Published: 10/31/2023

Updated: 12/4/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.42

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2018-18505

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 1/29/2019

Reference Information

CVE: CVE-2018-18500, CVE-2018-18501, CVE-2018-18505

BID: 106781