CVE-2018-12385
Summary
| CVE | CVE-2018-12385 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-18 13:29:00 UTC |
| Updated | 2018-12-06 19:03:00 UTC |
| Description | A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-4304-1 firefox-esr |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Mozilla Firefox ESR Bugs Let Users Bypass Security Restrictions and Cause the Target User's Browser to Crash - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-4327-1 thunderbird |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox ESR 60.2.1 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Access Denied |
CONFIRM |
bugzilla.mozilla.org |
Issue Tracking, Permissions Required, Vendor Advisory |
| USN-3793-1: Thunderbird vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| USN-3778-1: Firefox vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] [DLA 1575-1] thunderbird security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Mozilla Firefox and Firefox ESR CVE-2018-12385 Denial of Service Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Mozilla Thunderbird: Multiple vulnerabilities (GLSA 201811-13) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox 62.0.2 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Mozilla Firefox: Multiple vulnerabilities (GLSA 201810-01) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Security vulnerabilities fixed in Thunderbird 60.2.1 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Mozilla Firefox Lets Users Cause the Target User's Browser to Crash - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690632 Free Berkeley Software Distribution (FreeBSD) Security Update for firefox (3284d948-140c-4a3e-aa76-3b440e2006a8)
- 710279 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 201810-01)
- 710285 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 201811-13)