CVE-2018-12383
published 2018-10-18CVE-2018-12383: If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because…
PriorityP423medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.46%
37.1th percentile
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 62.0-1 (sid) | firefox 62.0-1 (sid) |
| debian | firefox-esr | < firefox 62.0-1 (sid) | firefox 62.0-1 (sid) |
| debian | thunderbird | < firefox 62.0-1 (sid) | firefox 62.0-1 (sid) |
| mozilla | firefox | < 62.0 | 62.0 |
| mozilla | firefox | >= 0 < 62.0+build2-0ubuntu0.14.04.5 | 62.0+build2-0ubuntu0.14.04.5 |
| mozilla | firefox | >= 0 < 62.0+build2-0ubuntu0.14.04.4 | 62.0+build2-0ubuntu0.14.04.4 |
| mozilla | firefox | >= 0 < 62.0+build2-0ubuntu0.14.04.3 | 62.0+build2-0ubuntu0.14.04.3 |
| mozilla | firefox | >= 0 < 62.0+build2-0ubuntu0.16.04.5 | 62.0+build2-0ubuntu0.16.04.5 |
| mozilla | firefox | >= 0 < 62.0+build2-0ubuntu0.16.04.4 | 62.0+build2-0ubuntu0.16.04.4 |
| mozilla | firefox | >= 0 < 62.0+build2-0ubuntu0.16.04.3 | 62.0+build2-0ubuntu0.16.04.3 |
| mozilla | firefox | >= 0 < 62.0+build2-0ubuntu0.18.04.5 | 62.0+build2-0ubuntu0.18.04.5 |
| mozilla | firefox | >= 0 < 62.0+build2-0ubuntu0.18.04.4 | 62.0+build2-0ubuntu0.18.04.4 |
| mozilla | firefox | >= 0 < 62.0+build2-0ubuntu0.18.04.3 | 62.0+build2-0ubuntu0.18.04.3 |
| mozilla | firefox | >= unspecified < 62 | 62 |
| mozilla | firefox_esr | < 60.2.1 | 60.2.1 |
| mozilla | firefox_esr | >= unspecified < 60.2.1 | 60.2.1 |
| mozilla | thunderbird | < 60.2.1 | 60.2.1 |
| mozilla | thunderbird | >= 0 < 1:60.2.1-1 | 1:60.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:60.2.1-1 | 1:60.2.1-1 |
| mozilla | thunderbird | >= 0 < 1:60.2.1-1 | 1:60.2.1-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cvcq-m8cv-7r6g: If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible
ghsa_unreviewed·2022-05-13
CVE-2018-12383 [MEDIUM] CWE-522 GHSA-cvcq-m8cv-7r6g: If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.
OSV
CVE-2018-12383: If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible
osv·2018-10-18·CVSS 5.5
CVE-2018-12383 [MEDIUM] CVE-2018-12383: If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.
OSV
thunderbird vulnerabilities
osv·2018-10-15·CVSS 9.8
CVE-2018-12376 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
or execute arbitrary code. (CVE-2018-12376, CVE-2018-12377,
CVE-2018-12378)
It was discovered that if a user saved passwords before Thunderbird 58 and
then later set a master password, an unencrypted copy of these passwords
would still be accessible. A local user could exploit this to obtain
sensitive information. (CVE-2018-12383)
A crash was discovered in TransportSecurityInfo used for SSL, which could
be triggered by data stored in the local cache directory. An attacker
could potentially exploit this in combination with another vulnerability
OSV
firefox regressions
osv·2018-09-17·CVSS 8.8
[HIGH] firefox regressions
firefox regressions
USN-3761-1 fixed vulnerabilities in Firefox. The update caused several
regressions affecting spellchecker dictionaries and search engines, which
were partially fixed by USN-3761-2. This update contains the remaining fix.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2018-12375, CVE-2018-12376, CVE-2018-12377,
CVE-2018-12378)
It was discovered that if a user saved passwords before Firefox 58 and
then later set a primary password, an unencrypted copy of these passwords
would still be accessible. A local user could exploit this to
OSV
firefox regressions
osv·2018-09-13·CVSS 8.8
CVE-2018-12375 [HIGH] firefox regressions
firefox regressions
USN-3761-1 fixed vulnerabilities in Firefox. The update caused several
regressions affecting spellchecker dictionaries and search engines. This
update fixes the problems.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2018-12375, CVE-2018-12376, CVE-2018-12377,
CVE-2018-12378)
It was discovered that if a user saved passwords before Firefox 58 and
then later set a master password, an unencrypted copy of these passwords
would still be accessible. A local user could exploit this to obtain
sensitive information. (CVE-2018-12383)
OSV
firefox vulnerabilities
osv·2018-09-06·CVSS 8.8
CVE-2018-12375 [HIGH] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2018-12375, CVE-2018-12376, CVE-2018-12377,
CVE-2018-12378)
It was discovered that if a user saved passwords before Firefox 58 and
then later set a primary password, an unencrypted copy of these passwords
would still be accessible. A local user could exploit this to obtain
sensitive information. (CVE-2018-12383)
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2018-10-15·CVSS 9.8
CVE-2018-12376 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
or execute arbitrary code. (CVE-2018-12376, CVE-2018-12377,
CVE-2018-12378)
It was discovered that if a user saved passwords before Thunderbird 58 and
then later set a master password, an unencrypted copy of these passwords
would still be accessible. A local user could exploit this to obtain
sensitive information. (CVE-2018-12383)
A crash was discovered in TransportSecurityInfo used for SSL, which could
be triggered by data stored in the local cache directory. An attacker
could
Ubuntu
Firefox regressions
vendor_ubuntu·2018-09-17·CVSS 8.8
[HIGH] Firefox regressions
Title: Firefox regressions
Summary: USN-3761-1 caused several regressions in Firefox.
USN-3761-1 fixed vulnerabilities in Firefox. The update caused several
regressions affecting spellchecker dictionaries and search engines, which
were partially fixed by USN-3761-2. This update contains the remaining fix.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2018-12375, CVE-2018-12376, CVE-2018-12377,
CVE-2018-12378)
It was discovered that if a user saved passwords before Firefox 58 and
then later set a primary password, an unencrypted copy of these pass
Ubuntu
Firefox regressions
vendor_ubuntu·2018-09-13·CVSS 8.8
[HIGH] Firefox regressions
Title: Firefox regressions
Summary: USN-3761-1 caused several regressions in Firefox.
USN-3761-1 fixed vulnerabilities in Firefox. The update caused several
regressions affecting spellchecker dictionaries and search engines. This
update fixes the problems.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2018-12375, CVE-2018-12376, CVE-2018-12377,
CVE-2018-12378)
It was discovered that if a user saved passwords before Firefox 58 and
then later set a master password, an unencrypted copy of these passwords
would still be accessible. A local user could
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2018-09-06·CVSS 8.8
CVE-2018-12375 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2018-12375, CVE-2018-12376, CVE-2018-12377,
CVE-2018-12378)
It was discovered that if a user saved passwords before Firefox 58 and
then later set a primary password, an unencrypted copy of these passwords
would still be accessible. A local user could exploit this to obtain
sensitive information. (CVE-2018-12383)
Instructions: After a standard system update you need to restart Firefox to make
all the necessary changes.
Red Hat
Mozilla: Setting a master password post-Firefox 58 does not delete unencrypted previously stored passwords
vendor_redhat·2018-09-05·CVSS 5.5
CVE-2018-12383 [MEDIUM] CWE-212 Mozilla: Setting a master password post-Firefox 58 does not delete unencrypted previously stored passwords
Mozilla: Setting a master password post-Firefox 58 does not delete unencrypted previously stored passwords
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.
Statement: Upstream decided to not fix this issue in Firefox ESR 60.2 given the low impact. A future ESR update may correct this flaw.
This flaw would impact users who had saved passwords from
Debian
CVE-2018-12383: firefox - If a user saved passwords before Firefox 58 and then later set a master password...
vendor_debian·2018·CVSS 5.5
CVE-2018-12383 [MEDIUM] CVE-2018-12383: firefox - If a user saved passwords before Firefox 58 and then later set a master password...
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.
Scope: local
sid: resolved (fixed in 62.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
key3.db encryption key remains on disk from Thunderbird 52.x (becomes issue if adding a master password post 60.x)
bugzilla·2020-01-02
[MEDIUM] key3.db encryption key remains on disk from Thunderbird 52.x (becomes issue if adding a master password post 60.x)
key3.db encryption key remains on disk from Thunderbird 52.x (becomes issue if adding a master password post 60.x)
We haven't yet fixed bug 1475775 in Thunderbird.
Because of the risk of key dataloss (e.g. bug 1510212), we're waiting for a solution that is more reliable than what Firefox had used as a fix.
Let's use this new bug to track fixing the issue in Thunderbird.
In separate NSS bug 1561368 we're working out an appropriate solution, potentially at the NSS code level.
Discussion:
Created attachment 9119187
testing-bug-1606619.txt
---
Created attachment 9119188
1606619-v1.patch (intended for the fork of the Mozilla repository used by Thunderbird 68.x)
---
The attached patch applies to TB 68.x, only.
The patch doesn't make sense for any later Thunderbird versions, because:
-
Bugzilla
CVE-2018-12383 Mozilla: Setting a master password post-Firefox 58 does not delete unencrypted previously stored passwords
bugzilla·2018-09-05·CVSS 5.5
CVE-2018-12383 [MEDIUM] CVE-2018-12383 Mozilla: Setting a master password post-Firefox 58 does not delete unencrypted previously stored passwords
CVE-2018-12383 Mozilla: Setting a master password post-Firefox 58 does not delete unencrypted previously stored passwords
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-20/#CVE-2018-12383
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Jurgen Gaeremyn
---
More information including wontfix decision in the upstream ticket:
https://
http://www.securityfocus.com/bid/105276http://www.securitytracker.com/id/1041610http://www.securitytracker.com/id/1041701https://access.redhat.com/errata/RHSA-2018:2834https://access.redhat.com/errata/RHSA-2018:2835https://access.redhat.com/errata/RHSA-2018:3403https://access.redhat.com/errata/RHSA-2018:3458https://bugzilla.mozilla.org/show_bug.cgi?id=1475775https://lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlhttps://security.gentoo.org/glsa/201810-01https://security.gentoo.org/glsa/201811-13https://usn.ubuntu.com/3761-1/https://usn.ubuntu.com/3793-1/https://www.debian.org/security/2018/dsa-4304https://www.debian.org/security/2018/dsa-4327https://www.mozilla.org/security/advisories/mfsa2018-20/https://www.mozilla.org/security/advisories/mfsa2018-23/https://www.mozilla.org/security/advisories/mfsa2018-25/http://www.securityfocus.com/bid/105276http://www.securitytracker.com/id/1041610http://www.securitytracker.com/id/1041701https://access.redhat.com/errata/RHSA-2018:2834https://access.redhat.com/errata/RHSA-2018:2835https://access.redhat.com/errata/RHSA-2018:3403https://access.redhat.com/errata/RHSA-2018:3458https://bugzilla.mozilla.org/show_bug.cgi?id=1475775https://lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlhttps://security.gentoo.org/glsa/201810-01https://security.gentoo.org/glsa/201811-13https://usn.ubuntu.com/3761-1/https://usn.ubuntu.com/3793-1/https://www.debian.org/security/2018/dsa-4304https://www.debian.org/security/2018/dsa-4327https://www.mozilla.org/security/advisories/mfsa2018-20/https://www.mozilla.org/security/advisories/mfsa2018-23/https://www.mozilla.org/security/advisories/mfsa2018-25/
2018-10-18
Published