PT-2018-3165 · Mozilla+4 · Firefox Esr+6

Holger Fuhrmannek

·

Published

2018-09-05

·

Updated

2024-12-12

·

CVE-2018-12379

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 62 Firefox ESR versions prior to 60.2 Thunderbird versions prior to 60.2.1
Description The issue is related to an out-of-bounds write that can be triggered when the Mozilla Updater opens a MAR format file containing a very long item filename, potentially leading to a crash. This can be exploited by running the Mozilla Updater manually on the local system with a malicious MAR file. The vulnerability may allow an attacker to execute arbitrary code using a specially crafted .MAR file.
Recommendations For Firefox versions prior to 62, update to version 62 or later to resolve the issue. For Firefox ESR versions prior to 60.2, update to version 60.2 or later to resolve the issue. For Thunderbird versions prior to 60.2.1, update to version 60.2.1 or later to resolve the issue.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2304
ALT-PU-2018-2423
ALT-PU-2018-2669
ALT-PU-2019-2324
ALT-PU-2019-2486
BDU:2019-04296
CESA-2018_2692
CESA-2018_2693
CESA-2018_3403
CVE-2018-12379
DLA-1575-1
DSA-4327-1
MGASA-2018-0480
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
RHSA-2018:2692
RHSA-2018:2693
RHSA-2018:3403
RHSA-2018:3458
RHSA-2018_2692
RHSA-2018_2693
RHSA-2018_3403
RHSA-2018_3458
SUSE-SU-2018:2890-1
SUSE-SU-2018:3591-1
SUSE-SU-2018:3591-2

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird