First published: Tue Jan 29 2019(Updated: )
A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, although the sound is still being played asynchronously, leading to a potentially exploitable crash.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <60.5 | 60.5 |
Mozilla Thunderbird | <65.0 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.6.0-1~deb10u1 1:102.13.1-1~deb11u1 1:115.6.0-1~deb11u1 1:115.5.0-1~deb12u1 1:115.6.0-1~deb12u1 1:115.6.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-18512 is a use-after-free vulnerability that can occur while playing a sound notification in Thunderbird.
The use-after-free vulnerability in CVE-2018-18512 occurs when the memory storing the sound data is immediately freed while the sound is still being played asynchronously.
CVE-2018-18512 can lead to a potentially exploitable crash in Thunderbird.
Thunderbird versions < 60.5 are affected by CVE-2018-18512.
To mitigate the vulnerability in CVE-2018-18512, update Thunderbird to version 60.5 or higher.