UBUNTU-CVE-2018-12392
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-12392
UBUNTU-CVE-2018-12392
Summary:
Details: When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
References: https://ubuntu.com/security/CVE-2018-12392, https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12392, https://www.mozilla.org/en-US/security/advisories/mfsa2018-26/#CVE-2018-12392, https://www.mozilla.org/en-US/security/advisories/mfsa2018-28/#CVE-2018-12392, https://ubuntu.com/security/notices/USN-3801-1, https://ubuntu.com/security/notices/USN-3868-1, https://www.cve.org/CVERecord?id=CVE-2018-12392
Affected packages
Package
Name: firefox
Purl: pkg:deb/ubuntu/[email protected]+build2-0ubuntu0.14.04.2?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
