PT-2018-3165 · Mozilla+4 · Firefox Esr+6
Holger Fuhrmannek
·
Publicado
2018-09-05
·
Atualizado
2024-12-12
·
CVE-2018-12379
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 62
Firefox ESR versions prior to 60.2
Thunderbird versions prior to 60.2.1
Description
The issue is related to an out-of-bounds write that can be triggered when the Mozilla Updater opens a MAR format file containing a very long item filename, potentially leading to a crash. This can be exploited by running the Mozilla Updater manually on the local system with a malicious MAR file. The vulnerability may allow an attacker to execute arbitrary code using a specially crafted .MAR file.
Recommendations
For Firefox versions prior to 62, update to version 62 or later to resolve the issue.
For Firefox ESR versions prior to 60.2, update to version 60.2 or later to resolve the issue.
For Thunderbird versions prior to 60.2.1, update to version 60.2.1 or later to resolve the issue.
Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird