CVE-2018-18500
published 2019-02-05CVE-2018-18500: A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being…
PriorityP347critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
12.66%
95.8th percentile
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 65.0-1 (sid) | firefox 65.0-1 (sid) |
| debian | firefox-esr | < firefox 65.0-1 (sid) | firefox 65.0-1 (sid) |
| debian | thunderbird | < firefox 65.0-1 (sid) | firefox 65.0-1 (sid) |
| mozilla | firefox | < 65.0 | 65.0 |
| mozilla | firefox | >= 0 < 65.0+build2-0ubuntu0.14.04.1 | 65.0+build2-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 65.0+build2-0ubuntu0.16.04.1 | 65.0+build2-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 65.0+build2-0ubuntu0.18.04.1 | 65.0+build2-0ubuntu0.18.04.1 |
| mozilla | firefox_esr | < 60.5 | 60.5 |
| mozilla | thunderbird | < 60.5 | 60.5 |
| mozilla | thunderbird | >= 0 < 1:60.5.0-1 | 1:60.5.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.5.0-1 | 1:60.5.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.5.0-1 | 1:60.5.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.5.0-1 | 1:60.5.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1+build2-0ubuntu0.14.04.1 | 1:60.5.1+build2-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1+build2-0ubuntu0.16.04.1 | 1:60.5.1+build2-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1+build2-0ubuntu0.18.04.1 | 1:60.5.1+build2-0ubuntu0.18.04.1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6hxm-h9g7-cg3m: A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements
ghsa_unreviewed·2022-05-14
CVE-2018-18500 [CRITICAL] CWE-416 GHSA-6hxm-h9g7-cg3m: A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
OSV
thunderbird vulnerabilities
osv·2019-02-26·CVSS 5.5
CVE-2016-5824 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
A use-after-free was discovered in libical. If a user were tricked in to
opening a specially crafted ICS calendar file, an attacker could
potentially exploit this to cause a denial of service. (CVE-2016-5824)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2018-18356, CVE-2018-18500, CVE-2019-5785)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
gain additional privileges by escaping the sandbox, or execute arbitr
OSV
CVE-2018-18500: A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements
osv·2019-02-05·CVSS 9.8
CVE-2018-18500 [CRITICAL] CVE-2018-18500: A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
OSV
firefox vulnerabilities
osv·2019-01-30·CVSS 9.8
CVE-2018-18500 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, gain additional
privileges by escaping the sandbox, or execute arbitrary code.
(CVE-2018-18500, CVE-2018-18501, CVE-2018-18502, CVE-2018-18503,
CVE-2018-18504, CVE-2018-18505)
It was discovered that Firefox allowed PAC files to specify that requests
to localhost are sent through the proxy to another server. If proxy
auto-detection is enabled, an attacker could potentially exploit this to
conduct attacks on local services and tools. (CVE-2018-18506)
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2019-02-26·CVSS 5.5
CVE-2016-5824 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
A use-after-free was discovered in libical. If a user were tricked in to
opening a specially crafted ICS calendar file, an attacker could
potentially exploit this to cause a denial of service. (CVE-2016-5824)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2018-18356, CVE-2018-18500, CVE-2019-5785)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
g
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2019-01-30·CVSS 9.8
CVE-2018-18500 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, gain additional
privileges by escaping the sandbox, or execute arbitrary code.
(CVE-2018-18500, CVE-2018-18501, CVE-2018-18502, CVE-2018-18503,
CVE-2018-18504, CVE-2018-18505)
It was discovered that Firefox allowed PAC files to specify that requests
to localhost are sent through the proxy to another server. If proxy
auto-detection is enabled, an attacker could potentially exploit this to
conduct attacks on local services and tools. (CVE-2018-18506)
Instructions: A
Red Hat
Mozilla: Use-after-free parsing HTML5 stream
vendor_redhat·2019-01-29·CVSS 9.8
CVE-2018-18500 [CRITICAL] CWE-416 Mozilla: Use-after-free parsing HTML5 stream
Mozilla: Use-after-free parsing HTML5 stream
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-18500: firefox - A use-after-free vulnerability can occur while parsing an HTML5 stream in concer...
vendor_debian·2018·CVSS 9.8
CVE-2018-18500 [CRITICAL] CVE-2018-18500: firefox - A use-after-free vulnerability can occur while parsing an HTML5 stream in concer...
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
Scope: local
sid: resolved (fixed in 65.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-18500 Mozilla: Use-after-free parsing HTML5 stream
bugzilla·2019-01-29·CVSS 9.8
CVE-2018-18500 [CRITICAL] CVE-2018-18500 Mozilla: Use-after-free parsing HTML5 stream
CVE-2018-18500 Mozilla: Use-after-free parsing HTML5 stream
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-02/#CVE-2018-18500
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Yaniv Frank (SophosLabs)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2019:0218 https://access.redhat.com/errata/RHSA-2019:0218
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:0219 https://access.redhat.com/errata/RHSA-2019:0219
arXiv
xTag: Mitigating Use-After-Free Vulnerabilities via Software-Based Pointer Tagging on Intel x86-64
arxiv_fulltext·2022-03-08
xTag: Mitigating Use-After-Free Vulnerabilities via Software-Based Pointer Tagging on Intel x86-64
: Mitigating Use-After-Free Vulnerabilities
via Software-Based Pointer Tagging on Intel x86-64
Lukas Bernhard1, Michael Rodler2, Thorsten Holz3, and Lucas Davi2
1Ruhr University Bochum, Email:\lukas.bernhard\@rub.de
2University of Duisburg-Essen, Email: \michael.rodler, lucas.davi\@uni-due.de
3 CISPA Helmholtz Center for
Information Security, Email: \holz\@cispa.de
## Abstract
Memory safety in complex applications implemented in unsafe programming languages such as C/ is still an unresolved problem in practice. Such applications were often developed in an ad-hoc, security-ignorant fashion, and thus they contain many types of security issues.
Many different types of defenses have been proposed in the past to mitigate these problems, some of which are even widely used in practice.
However
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00021.htmlhttp://www.securityfocus.com/bid/106781https://access.redhat.com/errata/RHSA-2019:0218https://access.redhat.com/errata/RHSA-2019:0219https://access.redhat.com/errata/RHSA-2019:0269https://access.redhat.com/errata/RHSA-2019:0270https://lists.debian.org/debian-lts-announce/2019/01/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2019/02/msg00024.htmlhttps://security.gentoo.org/glsa/201903-04https://security.gentoo.org/glsa/201904-07https://usn.ubuntu.com/3874-1/https://usn.ubuntu.com/3897-1/https://www.debian.org/security/2019/dsa-4376https://www.debian.org/security/2019/dsa-4392https://www.mozilla.org/security/advisories/mfsa2019-01/https://www.mozilla.org/security/advisories/mfsa2019-02/https://www.mozilla.org/security/advisories/mfsa2019-03/http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00021.htmlhttp://www.securityfocus.com/bid/106781https://access.redhat.com/errata/RHSA-2019:0218https://access.redhat.com/errata/RHSA-2019:0219https://access.redhat.com/errata/RHSA-2019:0269https://access.redhat.com/errata/RHSA-2019:0270https://lists.debian.org/debian-lts-announce/2019/01/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2019/02/msg00024.htmlhttps://security.gentoo.org/glsa/201903-04https://security.gentoo.org/glsa/201904-07https://usn.ubuntu.com/3874-1/https://usn.ubuntu.com/3897-1/https://www.debian.org/security/2019/dsa-4376https://www.debian.org/security/2019/dsa-4392https://www.mozilla.org/security/advisories/mfsa2019-01/https://www.mozilla.org/security/advisories/mfsa2019-02/https://www.mozilla.org/security/advisories/mfsa2019-03/
2019-02-05
Published