Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-12383

Опубликовано: 18 окт. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1
CVSS3: 5.5

Описание

If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.

РелизСтатусПримечание
bionic

released

62.0+build2-0ubuntu0.18.04.3
devel

released

62.0+build2-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [62.0+build2-0ubuntu0.14.04.3]]
precise/esm

DNE

trusty

released

62.0+build2-0ubuntu0.14.04.3
trusty/esm

DNE

trusty was released [62.0+build2-0ubuntu0.14.04.3]
upstream

needs-triage

xenial

released

62.0+build2-0ubuntu0.16.04.3

Показывать по

РелизСтатусПримечание
bionic

released

1:60.2.1+build1-0ubuntu0.18.04.2
devel

released

1:60.2.1+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:60.2.1+build1-0ubuntu0.14.04.2]]
precise/esm

DNE

trusty

released

1:60.2.1+build1-0ubuntu0.14.04.2
trusty/esm

DNE

trusty was released [1:60.2.1+build1-0ubuntu0.14.04.2]
upstream

released

60.2.1
xenial

released

1:60.2.1+build1-0ubuntu0.16.04.4

Показывать по

EPSS

Процентиль: 22%
0.00071
Низкий

2.1 Low

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
почти 7 лет назад

If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.

CVSS3: 5.5
nvd
почти 7 лет назад

If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.

CVSS3: 5.5
debian
почти 7 лет назад

If a user saved passwords before Firefox 58 and then later set a maste ...

CVSS3: 5.5
github
около 3 лет назад

If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.

CVSS3: 5.5
fstec
почти 7 лет назад

Уязвимость веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, связанная с хранением паролей в незашифрованном виде, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 22%
0.00071
Низкий

2.1 Low

CVSS2

5.5 Medium

CVSS3