Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-12377

Опубликовано: 18 окт. 2018
Источник: debian

Описание

A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed62.0-1package
firefox-esrfixed60.2.0esr-1package
thunderbirdfixed1:60.2.1-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-20/#CVE-2018-12377

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-21/#CVE-2018-12377

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-25/#CVE-2018-12377

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 7 лет назад

A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 9.8
redhat
почти 7 лет назад

A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 9.8
nvd
почти 7 лет назад

A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 9.8
github
около 3 лет назад

A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость веб-браузеров Firefox и Firefox ESR и почтового клиента Thunderbird, связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код или вызвать аварийное завершение работы приложения