PT-2018-3165 · Mozilla+4 · Firefox Esr+6
Holger Fuhrmannek
·
Published
2018-09-05
·
Updated
2024-12-12
·
CVE-2018-12379
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 62
Firefox ESR versions prior to 60.2
Thunderbird versions prior to 60.2.1
Description
The issue is related to an out-of-bounds write that can be triggered when the Mozilla Updater opens a MAR format file containing a very long item filename, potentially leading to a crash. This can be exploited by running the Mozilla Updater manually on the local system with a malicious MAR file. The vulnerability may allow an attacker to execute arbitrary code using a specially crafted .MAR file.
Recommendations
For Firefox versions prior to 62, update to version 62 or later to resolve the issue.
For Firefox ESR versions prior to 60.2, update to version 60.2 or later to resolve the issue.
For Thunderbird versions prior to 60.2.1, update to version 60.2.1 or later to resolve the issue.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Firefox
Firefox Esr
Red Hat
Suse
Thunderbird