Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12365

Опубликовано: 18 окт. 2018
Источник: debian
EPSS Низкий

Описание

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefox-esrfixed52.9.0esr-1package
firefoxfixed61.0-1package
thunderbirdfixed1:52.9.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-15/#CVE-2018-12365

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-17/#CVE-2018-12365

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-18/#CVE-2018-12365

EPSS

Процентиль: 83%
0.02054
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 7 лет назад

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.1
redhat
больше 7 лет назад

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.5
nvd
около 7 лет назад

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.5
github
больше 3 лет назад

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость браузеров Firefox и Firefox ESR и почтового клиента Thunderbird, связанная с ошибками межпроцессного взаимодействия (IPC), позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 83%
0.02054
Низкий