CVE Database
/

CVE-2018-12385

Back to search

CVE-2018-12385

Published: Oct 18, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.

VendorProductVersions

Mozilla

Thunderbird

affected
unspecified - < 60.2.1

Mozilla

Firefox ESR

affected
unspecified - < 60.2.1

Mozilla

Firefox

affected
unspecified - < 62.0.2

References

GLSA-201810-01
vendor-advisory
x_refsource_GENTOO
105380
vdb-entry
x_refsource_BID
GLSA-201811-13
vendor-advisory
x_refsource_GENTOO
USN-3778-1
vendor-advisory
x_refsource_UBUNTU
DSA-4327
vendor-advisory
x_refsource_DEBIAN
1041700
vdb-entry
x_refsource_SECTRACK
RHSA-2018:2835
vendor-advisory
x_refsource_REDHAT
RHSA-2018:3403
vendor-advisory
x_refsource_REDHAT
1041701
vdb-entry
x_refsource_SECTRACK
RHSA-2018:3458
vendor-advisory
x_refsource_REDHAT
DSA-4304
vendor-advisory
x_refsource_DEBIAN
RHSA-2018:2834
vendor-advisory
x_refsource_REDHAT
USN-3793-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now