UBUNTU-CVE-2018-18512
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-18512
Summary:
Details: A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, although the sound is still being played asynchronously, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5.
References: https://ubuntu.com/security/CVE-2018-18512, https://www.mozilla.org/en-US/security/advisories/mfsa2019-03/#CVE-2018-18512, https://bugzilla.mozilla.org/show_bug.cgi?id=1482659, https://www.mozilla.org/security/advisories/mfsa2019-03/, https://www.cve.org/CVERecord?id=CVE-2018-18512
Affected packages
Package
Name: thunderbird
Purl: pkg:deb/ubuntu/thunderbird@1:60.6.1+build2-0ubuntu0.16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
