CVE-2018-12379
published 2018-10-18CVE-2018-12379: When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially…
PriorityP335high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.39%
31.6th percentile
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 62.0-1 (sid) | firefox 62.0-1 (sid) |
| debian | firefox-esr | < firefox 62.0-1 (sid) | firefox 62.0-1 (sid) |
| debian | thunderbird | < firefox 62.0-1 (sid) | firefox 62.0-1 (sid) |
| mozilla | firefox | < 60.2.0 | 60.2.0 |
| mozilla | firefox | < 62.0 | 62.0 |
| mozilla | firefox | >= unspecified < 62 | 62 |
| mozilla | firefox_esr | >= unspecified < 60.2 | 60.2 |
| mozilla | thunderbird | < 60.2.1 | 60.2.1 |
| mozilla | thunderbird | >= 0 < 1:60.2.1-1 | 1:60.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:60.2.1-1 | 1:60.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:60.2.1-1 | 1:60.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:60.2.1-1 | 1:60.2.1-1 |
| mozilla | thunderbird | >= unspecified < 60.2.1 | 60.2.1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-77mg-phf5-3h8g: When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a poten
ghsa_unreviewed·2022-05-14
CVE-2018-12379 [HIGH] CWE-787 GHSA-77mg-phf5-3h8g: When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a poten
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
OSV
CVE-2018-12379: When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a poten
osv·2018-10-18·CVSS 7.8
CVE-2018-12379 [HIGH] CVE-2018-12379: When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a poten
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
Red Hat
Mozilla: Out-of-bounds write with malicious MAR file
vendor_redhat·2018-09-05·CVSS 7.8
CVE-2018-12379 [HIGH] CWE-787 Mozilla: Out-of-bounds write with malicious MAR file
Mozilla: Out-of-bounds write with malicious MAR file
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
Statement: This flaw cannot be exploited through email in Thunderbird as scripting is disabled in this for email content. It may be possible to exploit through Feeds (Atom or RSS) or other browser-like contexts.
Debian
CVE-2018-12379: firefox - When the Mozilla Updater opens a MAR format file which contains a very long item...
vendor_debian·2018·CVSS 7.8
CVE-2018-12379 [HIGH] CVE-2018-12379: firefox - When the Mozilla Updater opens a MAR format file which contains a very long item...
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
Scope: local
sid: resolved (fixed in 62.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12379 Mozilla: Out-of-bounds write with malicious MAR file
bugzilla·2018-09-05·CVSS 7.8
CVE-2018-12379 [HIGH] CVE-2018-12379 Mozilla: Out-of-bounds write with malicious MAR file
CVE-2018-12379 Mozilla: Out-of-bounds write with malicious MAR file
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-21/#CVE-2018-12379
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:2692 https://access.redhat.com/errata/RHSA-2018:2692
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Bugzilla
CVE-2017-12374 CVE-2017-12375 CVE-2017-12376 CVE-2017-12377 CVE-2017-12378 CVE-2017-12379 CVE-2017-12380 clamav: Multiple vulnerabilities fixed in 0.99.3
bugzilla·2018-01-29·CVSS 7.5
CVE-2017-12374 [HIGH] CVE-2017-12374 CVE-2017-12375 CVE-2017-12376 CVE-2017-12377 CVE-2017-12378 CVE-2017-12379 CVE-2017-12380 clamav: Multiple vulnerabilities fixed in 0.99.3
CVE-2017-12374 CVE-2017-12375 CVE-2017-12376 CVE-2017-12377 CVE-2017-12378 CVE-2017-12379 CVE-2017-12380 clamav: Multiple vulnerabilities fixed in 0.99.3
Multiple security bugs fixed in clamav 0.99.3.
References:
http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html
Discussion:
Created clamav tracking bugs for this issue:
Affects: epel-all [bug 1539864]
Affects: fedora-all [bug 1539865]
---
Can we close this bug ? , since clamav 0.99.4 already available in all branches
---
(In reply to Sergio Monteiro Basto from comment #2)
> Can we close this bug ? , since clamav 0.99.4 already available in all
> branches
Yes, closing.
http://www.securityfocus.com/bid/105280http://www.securitytracker.com/id/1041610https://access.redhat.com/errata/RHSA-2018:2692https://access.redhat.com/errata/RHSA-2018:2693https://access.redhat.com/errata/RHSA-2018:3403https://access.redhat.com/errata/RHSA-2018:3458https://bugzilla.mozilla.org/show_bug.cgi?id=1473113https://lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlhttps://security.gentoo.org/glsa/201810-01https://security.gentoo.org/glsa/201811-13https://www.debian.org/security/2018/dsa-4327https://www.mozilla.org/security/advisories/mfsa2018-20/https://www.mozilla.org/security/advisories/mfsa2018-21/https://www.mozilla.org/security/advisories/mfsa2018-25/http://www.securityfocus.com/bid/105280http://www.securitytracker.com/id/1041610https://access.redhat.com/errata/RHSA-2018:2692https://access.redhat.com/errata/RHSA-2018:2693https://access.redhat.com/errata/RHSA-2018:3403https://access.redhat.com/errata/RHSA-2018:3458https://bugzilla.mozilla.org/show_bug.cgi?id=1473113https://lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlhttps://security.gentoo.org/glsa/201810-01https://security.gentoo.org/glsa/201811-13https://www.debian.org/security/2018/dsa-4327https://www.mozilla.org/security/advisories/mfsa2018-20/https://www.mozilla.org/security/advisories/mfsa2018-21/https://www.mozilla.org/security/advisories/mfsa2018-25/
2018-10-18
Published