StackRadar

CVE-2018-5146

High

Advisory

Published 16 Mar 2018In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.119
96th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
2 of 2
affected packages

libvorbis - security update

Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
libvorbisdeb1.3.4-2, 1.3.5-3, 1.3.5-3ubuntu0.1, 1.3.5-41.3.4-2+deb8u1, 1.3.5-3ubuntu0.2, 1.3.5-4+deb9u211
firefoxdeb57.0.4+build1-0ubuntu0.16.04.159.0.1+build1-0ubuntu0.16.04.11
OSV records
UBUNTU-CVE-2018-5146DSA-4140-1
Also known as
USN-3599-1, USN-3604-1

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
hivedmwm-bigdataVerified publisher0.1.62 of 5See more

hive dmwm-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2018-5146.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
libvorbis@1.3.4-2
1.3.4-2+deb8u1
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
libvorbis@1.3.4-2
1.3.4-2+deb8u1

Open the chart page →

20,837
rocketmqgin1.1.01 of 2See more

rocketmq gin 1.1.0

1 of the 2 container images this version deploys carry CVE-2018-5146.

Container imageDigestPackageFixed in
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
libvorbis@1.3.4-2
1.3.4-2+deb8u1

Open the chart page →

9,154
tensorflow-notebookcloudnativeapp0.1.21 of 1See more

tensorflow-notebook cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2018-5146.

Container imageDigestPackageFixed in
tensorflow/tensorflow:1.6.0-devel1e3172090703
libvorbis@1.3.5-3ubuntu0.1
1.3.5-3ubuntu0.2

Open the chart page →

36,094
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2018-5146.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
libvorbis@1.3.4-2
1.3.4-2+deb8u1

Open the chart page →

6,882
distributed-tensorflowcloudnativeapp0.1.11 of 1See more

distributed-tensorflow cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2018-5146.

Container imageDigestPackageFixed in
cheyang/distributed-tf:1.6.046cc34755493
libvorbis@1.3.5-3ubuntu0.1
1.3.5-3ubuntu0.2

Open the chart page →

36,094
riemanncloudnativeapp0.1.21 of 1See more

riemann cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2018-5146.

Container imageDigestPackageFixed in
raykrueger/riemann:0.2.14c8baf3de57bb
libvorbis@1.3.5-4
1.3.5-4+deb9u2

Open the chart page →

6,497
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2018-5146.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
firefox@57.0.4+build1-0ubuntu0.16.04.1
libvorbis@1.3.5-3
59.0.1+build1-0ubuntu0.16.04.1
1.3.5-3ubuntu0.2

Open the chart page →

77,758
webpagetest-servercloudnativeapp0.2.11 of 1See more

webpagetest-server cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2018-5146.

Container imageDigestPackageFixed in
timothyclarke/wptserver:2018-03-0840a80ced8031
libvorbis@1.3.4-2
1.3.4-2+deb8u1

Open the chart page →

3,716
hivegradiant-bigdataVerified publisher0.1.62 of 5See more

hive gradiant-bigdata 0.1.6

2 of the 5 container images this version deploys carry CVE-2018-5146.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
libvorbis@1.3.4-2
1.3.4-2+deb8u1
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
libvorbis@1.3.4-2
1.3.4-2+deb8u1

Open the chart page →

20,837
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2018-5146.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
libvorbis@1.3.4-2
1.3.4-2+deb8u1

Open the chart page →

6,882
hapi-fhirhapi-fhirVerified publisher0.1.01 of 1See more

hapi-fhir hapi-fhir 0.1.0

1 of the 1 container images this version deploys carry CVE-2018-5146.

Container imageDigestPackageFixed in
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
libvorbis@1.3.4-2
1.3.4-2+deb8u1

Open the chart page →

6,362
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2018-5146.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
libvorbis@1.3.5-4
1.3.5-4+deb9u2

Open the chart page →

10,682
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2018-5146.

Container imageDigestPackageFixed in
ncsapolyglot/converters-avconv:latestc44b22eb58bb
libvorbis@1.3.5-4
1.3.5-4+deb9u2

Open the chart page →

55,726

Container images carrying it

11 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
bde2020/hive:2.3.2-postgresql-metastore620267768985
libvorbis@1.3.4-2
1.3.4-2+deb8u1
4
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
libvorbis@1.3.4-2
1.3.4-2+deb8u1
2
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
libvorbis@1.3.4-2
1.3.4-2+deb8u1
1
cheyang/distributed-tf:1.6.046cc34755493
libvorbis@1.3.5-3ubuntu0.1
1.3.5-3ubuntu0.2
1
jenkinsci/jenkins:2.67a1f33f004659
libvorbis@1.3.5-4
1.3.5-4+deb9u2
1
ncsapolyglot/converters-avconv:latestc44b22eb58bb
libvorbis@1.3.5-4
1.3.5-4+deb9u2
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
libvorbis@1.3.4-2
1.3.4-2+deb8u1
1
raykrueger/riemann:0.2.14c8baf3de57bb
libvorbis@1.3.5-4
1.3.5-4+deb9u2
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
libvorbis@1.3.5-3ubuntu0.1
1.3.5-3ubuntu0.2
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
firefox@57.0.4+build1-0ubuntu0.16.04.1
libvorbis@1.3.5-3
59.0.1+build1-0ubuntu0.16.04.1
1.3.5-3ubuntu0.2
1
timothyclarke/wptserver:2018-03-0840a80ced8031
libvorbis@1.3.4-2
1.3.4-2+deb8u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.