Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-12365

Опубликовано: 18 окт. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.5

Описание

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

РелизСтатусПримечание
artful

released

61.0+build3-0ubuntu0.17.10.1
bionic

released

61.0+build3-0ubuntu0.18.04.1
devel

released

61.0.1+build1-0ubuntu0.18.04.1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [61.0+build3-0ubuntu0.14.04.2]]
precise/esm

DNE

trusty

released

61.0+build3-0ubuntu0.14.04.2
trusty/esm

DNE

trusty was released [61.0+build3-0ubuntu0.14.04.2]
upstream

released

61.0
xenial

released

61.0+build3-0ubuntu0.16.04.2

Показывать по

РелизСтатусПримечание
artful

released

1:52.9.1+build3-0ubuntu0.17.10.1
bionic

released

1:52.9.1+build3-0ubuntu0.18.04.1
devel

released

1:60.2.1+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:52.9.1+build3-0ubuntu0.14.04.1]]
precise/esm

DNE

trusty

released

1:52.9.1+build3-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [1:52.9.1+build3-0ubuntu0.14.04.1]
upstream

released

52.9.0
xenial

released

1:52.9.1+build3-0ubuntu0.16.04.1

Показывать по

EPSS

Процентиль: 83%
0.02054
Низкий

4.3 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
redhat
больше 7 лет назад

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.5
nvd
около 7 лет назад

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.5
debian
около 7 лет назад

A compromised IPC child process can escape the content sandbox and lis ...

CVSS3: 6.5
github
больше 3 лет назад

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость браузеров Firefox и Firefox ESR и почтового клиента Thunderbird, связанная с ошибками межпроцессного взаимодействия (IPC), позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 83%
0.02054
Низкий

4.3 Medium

CVSS2

6.5 Medium

CVSS3