CVE-2018-12387
published 2018-10-18CVE-2018-12387: A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes…
critical9.1CVSS 3.0
AVNACLPRNUINSUCHINAH
A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 62.0.3-1 (sid) | firefox 62.0.3-1 (sid) |
| debian | firefox-esr | < firefox 62.0.3-1 (sid) | firefox 62.0.3-1 (sid) |
| mozilla | firefox | < 60.2.2 | 60.2.2 |
| mozilla | firefox | < 62.0.3 | 62.0.3 |
| mozilla | firefox | >= 0 < 62.0.3+build1-0ubuntu0.14.04.2 | 62.0.3+build1-0ubuntu0.14.04.2 |
| mozilla | firefox | >= 0 < 62.0.3+build1-0ubuntu0.16.04.2 | 62.0.3+build1-0ubuntu0.16.04.2 |
| mozilla | firefox | >= 0 < 62.0.3+build1-0ubuntu0.18.04.1 | 62.0.3+build1-0ubuntu0.18.04.1 |
| mozilla | firefox | >= unspecified < 62.0.3 | 62.0.3 |
| mozilla | firefox_esr | >= unspecified < 60.2.2 | 60.2.2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL