CVE-2018-12383
Summary
| CVE | CVE-2018-12383 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-18 13:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-4304-1 firefox-esr |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Mozilla Firefox ESR Bugs Let Users Bypass Security Restrictions and Cause the Target User's Browser to Crash - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-4327-1 thunderbird |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox ESR 60.2.1 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| USN-3761-1: Firefox vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox 62 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| USN-3793-1: Thunderbird vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] [DLA 1575-1] thunderbird security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Mozilla Firefox Multiple Bugs Let Remote Users Spoof the Address Bar, Bypass Security Restrictions, and Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| 1475775 - (CVE-2018-12383) key3.db encryption key remains on disk from pre-Firefox-58 (becomes issue if adding a master password post-58) |
CONFIRM |
bugzilla.mozilla.org |
Exploit, Issue Tracking, Vendor Advisory |
| Mozilla Thunderbird: Multiple vulnerabilities (GLSA 201811-13) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Mozilla Firefox MFSA2018-20 Multiple Security Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Mozilla Firefox: Multiple vulnerabilities (GLSA 201810-01) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Security vulnerabilities fixed in Thunderbird 60.2.1 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690611 Free Berkeley Software Distribution (FreeBSD) Security Update for mozilla (c96d416a-eae7-4d5d-bc84-40deca9329fb)
- 710279 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 201810-01)
- 710285 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 201811-13)