Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2018-12377

Published: 6 September 2018

A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

Priority

Medium

CVSS 3 base score: 9.8

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
bionic
Released (62.0+build2-0ubuntu0.18.04.3)
precise Does not exist

trusty Does not exist
(trusty was released [62.0+build2-0ubuntu0.14.04.3])
upstream Needs triage

xenial
Released (62.0+build2-0ubuntu0.16.04.3)
firefox-esr
Launchpad, Ubuntu, Debian
bionic Does not exist

precise Does not exist

trusty Does not exist

upstream
Released (60.2.0esr-1)
xenial Does not exist

thunderbird
Launchpad, Ubuntu, Debian
bionic
Released (1:60.2.1+build1-0ubuntu0.18.04.2)
precise Does not exist

trusty Does not exist
(trusty was released [1:60.2.1+build1-0ubuntu0.14.04.2])
upstream
Released (60.2.1)
xenial
Released (1:60.2.1+build1-0ubuntu0.16.04.4)