Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-12385

Опубликовано: 18 окт. 2018
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.4
CVSS3: 7

Описание

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.

РелизСтатусПримечание
bionic

released

62.0.3+build1-0ubuntu0.18.04.1
devel

released

62.0.3+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [62.0.3+build1-0ubuntu0.14.04.2]]
precise/esm

DNE

trusty

released

62.0.3+build1-0ubuntu0.14.04.2
trusty/esm

DNE

trusty was released [62.0.3+build1-0ubuntu0.14.04.2]
upstream

released

62.0.2
xenial

released

62.0.3+build1-0ubuntu0.16.04.2

Показывать по

РелизСтатусПримечание
bionic

released

1:60.2.1+build1-0ubuntu0.18.04.2
devel

released

1:60.2.1+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:60.2.1+build1-0ubuntu0.14.04.2]]
precise/esm

DNE

trusty

released

1:60.2.1+build1-0ubuntu0.14.04.2
trusty/esm

DNE

trusty was released [1:60.2.1+build1-0ubuntu0.14.04.2]
upstream

released

60.2.1
xenial

released

1:60.2.1+build1-0ubuntu0.16.04.4

Показывать по

EPSS

Процентиль: 22%
0.00071
Низкий

4.4 Medium

CVSS2

7 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
redhat
почти 7 лет назад

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.

CVSS3: 7
nvd
почти 7 лет назад

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.

CVSS3: 7
debian
почти 7 лет назад

A potentially exploitable crash in TransportSecurityInfo used for SSL ...

CVSS3: 7
github
около 3 лет назад

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.

CVSS3: 7
fstec
почти 7 лет назад

Уязвимость компонента TransportSecurityInfo веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 22%
0.00071
Низкий

4.4 Medium

CVSS2

7 High

CVSS3