First published: Tue Dec 11 2018(Updated: )
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the `select` element in the `options` collection. This results in a potentially exploitable crash. External Reference: <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2018-30/#CVE-2018-18492">https://www.mozilla.org/en-US/security/advisories/mfsa2018-30/#CVE-2018-18492</a>
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <60.4 | 60.4 |
Firefox | <64 | 64 |
Firefox ESR | <60.4 | 60.4 |
Firefox | <64.0 | |
Firefox ESR | <60.4.0 | |
Thunderbird | <60.4.0 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =18.10 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
debian/firefox | 137.0.1-1 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.9.0esr-1~deb11u1 128.8.0esr-1~deb12u1 128.9.0esr-1~deb12u1 128.9.0esr-2 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:128.9.0esr-1~deb11u1 1:128.8.0esr-1~deb12u1 1:128.9.0esr-1~deb12u1 1:128.9.0esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-18492 is a use-after-free vulnerability that can occur after deleting a selection element in Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
CVE-2018-18492 has a severity rating of 9.8 out of 10.
Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64 are affected by CVE-2018-18492.
The remedy for CVE-2018-18492 is to update Thunderbird to version 60.4 or later, Firefox ESR to version 60.4 or later, and Firefox to version 64 or later.
You can find more information about CVE-2018-18492 in the following references: [1] [2] [3].