PT-2019-9599 · Mozilla+1 · Thunderbird+1

Wayne Mery

·

Publicado

2019-01-29

·

Atualizado

2020-03-18

·

CVE-2018-18512

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Thunderbird versions prior to 60.5
Description A use-after-free issue can occur in Thunderbird when playing a sound notification. The memory containing the sound data is freed immediately, even though the sound is still being played asynchronously, which can lead to a potentially exploitable crash.
Recommendations For versions prior to 60.5, update to version 60.5 or later to resolve the issue.

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-1166
ALT-PU-2020-1515
CVE-2018-18512
DLA-1678-1
DSA-4392-1

Produtos afetados

Alt Linux
Thunderbird