CVE-2018-12378Use After Free in Mozilla Firefox

CWE-416Use After Free15 documents8 sources
Severity
9.8CRITICALNVD
OSV8.8
EPSS
3.1%
top 13.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 18
Latest updateMay 14

Description

A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages11 packages

CVEListV5mozilla/firefoxunspecified62
NVDmozilla/firefox< 60.2.0+1
CVEListV5mozilla/firefox_esrunspecified60.2
Ubuntumozilla/firefox< 62.0+build2-0ubuntu0.14.04.3+2
CVEListV5mozilla/thunderbirdunspecified60.2.1

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, Enterprise Linux 7.6, 7.5

🔴Vulnerability Details

7
GHSA
GHSA-393c-hwwh-9gm2: A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to2022-05-14
CVEList
CVE-2018-12378: A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to2018-10-18
OSV
CVE-2018-12378: A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to2018-10-18
OSV
thunderbird vulnerabilities2018-10-15
OSV
firefox regressions2018-09-17

📋Vendor Advisories

4
Ubuntu
Thunderbird vulnerabilities2018-10-15
Ubuntu
Firefox vulnerabilities2018-09-06
Red Hat
Mozilla: Use-after-free in IndexedDB2018-09-05
Debian
CVE-2018-12378: firefox - A use-after-free vulnerability can occur when an IndexedDB index is deleted whil...2018

💬Community

3
Bugzilla
CVE-2018-20839 systemd: mishandling of the current keyboard mode check leading to passwords being disclosed in cleartext to attacker2019-06-04
Bugzilla
CVE-2018-12378 Mozilla: Use-after-free in IndexedDB2018-09-05
Bugzilla
CVE-2017-12374 CVE-2017-12375 CVE-2017-12376 CVE-2017-12377 CVE-2017-12378 CVE-2017-12379 CVE-2017-12380 clamav: Multiple vulnerabilities fixed in 0.99.32018-01-29
CVE-2018-12378 — Use After Free in Mozilla Firefox | cvebase