Your submission was sent successfully! Close

CVE-2018-12360

Published: 27 June 2018

A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by focusing that element. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

Priority

Medium

CVSS 3 base score: 8.8

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
artful
Released (61.0+build3-0ubuntu0.17.10.1)
bionic
Released (61.0+build3-0ubuntu0.18.04.1)
precise Does not exist

trusty Does not exist
(trusty was released [61.0+build3-0ubuntu0.14.04.2])
upstream
Released (61.0)
xenial
Released (61.0+build3-0ubuntu0.16.04.2)
thunderbird
Launchpad, Ubuntu, Debian
artful
Released (1:52.9.1+build3-0ubuntu0.17.10.1)
bionic
Released (1:52.9.1+build3-0ubuntu0.18.04.1)
precise Does not exist

trusty Does not exist
(trusty was released [1:52.9.1+build3-0ubuntu0.14.04.1])
upstream
Released (52.9.0)
xenial
Released (1:52.9.1+build3-0ubuntu0.16.04.1)