Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12365

Опубликовано: 18 окт. 2018
Источник: debian
EPSS Низкий

Описание

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefox-esrfixed52.9.0esr-1package
firefoxfixed61.0-1package
thunderbirdfixed1:52.9.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-15/#CVE-2018-12365

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-17/#CVE-2018-12365

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-18/#CVE-2018-12365

EPSS

Процентиль: 87%
0.03158
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 8 лет назад

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.1
redhat
около 8 лет назад

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.5
nvd
почти 8 лет назад

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.5
github
около 4 лет назад

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.5
fstec
около 8 лет назад

Уязвимость браузеров Firefox и Firefox ESR и почтового клиента Thunderbird, связанная с ошибками межпроцессного взаимодействия (IPC), позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 87%
0.03158
Низкий