Alpine: firefox-esr: security update to 52.5.2-r0 (deprecated)

critical Tenable Self-Hosted Container Security Plugin ID 400757

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A use-after-free vulnerability can occur during font face manipulation when a font face is freed while
still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6,
Firefox ESR < 52.6, and Firefox < 58. (CVE-2018-5104)

- Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of
memory corruption and we presume that with enough effort that some of these could be exploited to run
arbitrary code. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
(CVE-2018-5089)

- A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers.
This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox
< 58. (CVE-2018-5091)

- An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some
systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a
potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and
Firefox < 58. (CVE-2018-5095)

- A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a
potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird < 52.6.
(CVE-2018-5096)

See Also

https://git.alpinelinux.org/aports/commit/?id=3946ebd9552031cbf702f41b55e9ca9d3b3c5c18

https://git.alpinelinux.org/aports/commit/?id=f21cbd7eaa510ec218e63fc43323ca9b101bdad6

Plugin Details

Severity: Critical

ID: 400757

Version: Revision 1.27

Type: Local

Published: 8/16/2023

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2018-5104

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/25/2018

Vulnerability Publication Date: 1/23/2018

Reference Information

CVE: CVE-2018-5089, CVE-2018-5091, CVE-2018-5095, CVE-2018-5096, CVE-2018-5097, CVE-2018-5098, CVE-2018-5099, CVE-2018-5102, CVE-2018-5103, CVE-2018-5104, CVE-2018-5117

BID: 102771, 102783