UBUNTU-CVE-2018-12378
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-12378
UBUNTU-CVE-2018-12378
Summary:
Details: A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
References: https://ubuntu.com/security/CVE-2018-12378, https://www.mozilla.org/en-US/security/advisories/mfsa2018-20/#CVE-2018-12378, https://www.mozilla.org/en-US/security/advisories/mfsa2018-21/#CVE-2018-12378, https://www.mozilla.org/en-US/security/advisories/mfsa2018-25/#CVE-2018-12378, https://ubuntu.com/security/notices/USN-3761-1, https://ubuntu.com/security/notices/USN-3793-1, https://www.cve.org/CVERecord?id=CVE-2018-12378
Affected packages
Package
Name: firefox
Purl: pkg:deb/ubuntu/[email protected]+build2-0ubuntu0.14.04.3?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
