CVE-2018-18512: Use After Free
A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, although the sound is still being played asynchronously, leading to a potentially exploitable crash.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-18512?
CVE-2018-18512 is a use-after-free vulnerability that can occur while playing a sound notification in Thunderbird.
How does the use-after-free vulnerability in CVE-2018-18512 occur?
The use-after-free vulnerability in CVE-2018-18512 occurs when the memory storing the sound data is immediately freed while the sound is still being played asynchronously.
What is the potential impact of CVE-2018-18512?
CVE-2018-18512 can lead to a potentially exploitable crash in Thunderbird.
Which versions of Thunderbird are affected by CVE-2018-18512?
Thunderbird versions < 60.5 are affected by CVE-2018-18512.
How can I mitigate the vulnerability in CVE-2018-18512?
To mitigate the vulnerability in CVE-2018-18512, update Thunderbird to version 60.5 or higher.