Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-12385

Опубликовано: 21 сент. 2018
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.

Отчет

This flaw cannot be exploited through email in Thunderbird as scripting is disabled in this for email content. It may be possible to exploit through Feeds (Atom or RSS) or other browser-like contexts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 6firefoxFixedRHSA-2018:283427.09.2018
Red Hat Enterprise Linux 6thunderbirdFixedRHSA-2018:340330.10.2018
Red Hat Enterprise Linux 7firefoxFixedRHSA-2018:283527.09.2018
Red Hat Enterprise Linux 7thunderbirdFixedRHSA-2018:345805.11.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1632062Mozilla: Crash in TransportSecurityInfo due to cached data

EPSS

Процентиль: 22%
0.00071
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
почти 7 лет назад

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.

CVSS3: 7
nvd
почти 7 лет назад

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.

CVSS3: 7
debian
почти 7 лет назад

A potentially exploitable crash in TransportSecurityInfo used for SSL ...

CVSS3: 7
github
около 3 лет назад

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.

CVSS3: 7
fstec
почти 7 лет назад

Уязвимость компонента TransportSecurityInfo веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 22%
0.00071
Низкий

6.1 Medium

CVSS3