First published: Tue Jun 26 2018(Updated: )
A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node being freed but the node still having a pointer referencing it. This results in a potentially exploitable crash.
Credit: security@mozilla.org security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.5 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
Debian | =8.0 | |
Debian | =9.0 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =17.10 | |
Ubuntu | =18.04 | |
Firefox | <61.0 | |
Firefox | >=53.0<60.1.0 | |
Firefox ESR | <52.9 | |
Thunderbird | <52.9 | |
Thunderbird | >=52.9.1<60.0 | |
Firefox ESR | >=53.0<60.1.0 | |
Thunderbird | <60 | 60 |
Thunderbird | <52.9 | 52.9 |
Firefox | <61 | 61 |
Firefox ESR | <60.1 | 60.1 |
Firefox ESR | <52.9 | 52.9 |
debian/firefox | 135.0.1-1 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.7.0esr-1~deb11u1 128.5.0esr-1~deb12u1 128.7.0esr-1~deb12u1 128.7.0esr-1 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:128.7.0esr-1~deb11u1 1:128.5.0esr-1~deb12u1 1:128.7.0esr-1~deb12u1 1:128.7.0esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2018-12363 is classified as a high-severity use-after-free vulnerability.
To fix CVE-2018-12363, update affected software like Mozilla Firefox or Thunderbird to the latest versions.
CVE-2018-12363 affects Mozilla Thunderbird versions up to 60, Firefox ESR versions up to 60.1, and Firefox versions up to 61.
Exploitation of CVE-2018-12363 could lead to potential crashes and unauthorized access due to use-after-free conditions.
If your software has been updated to a secure version, the risk associated with CVE-2018-12363 is mitigated.