cbcvebase.
CVE-2018-18505
published 2019-02-05

CVE-2018-18505: An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server…

PriorityP356critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
EPSS
4.54%
90.5th percentile
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianfirefox< firefox 65.0-1 (sid)firefox 65.0-1 (sid)
debianfirefox-esr< firefox 65.0-1 (sid)firefox 65.0-1 (sid)
debianthunderbird< firefox 65.0-1 (sid)firefox 65.0-1 (sid)
mozillafirefox< 60.5.060.5.0
mozillafirefox< 65.065.0
mozillafirefox>= 0 < 65.0+build2-0ubuntu0.14.04.165.0+build2-0ubuntu0.14.04.1
mozillafirefox>= 0 < 65.0+build2-0ubuntu0.16.04.165.0+build2-0ubuntu0.16.04.1
mozillafirefox>= 0 < 65.0+build2-0ubuntu0.18.04.165.0+build2-0ubuntu0.18.04.1
mozillathunderbird< 60.5.060.5.0
mozillathunderbird>= 0 < 1:60.5.0-11:60.5.0-1
mozillathunderbird>= 0 < 1:60.5.0-11:60.5.0-1
mozillathunderbird>= 0 < 1:60.5.0-11:60.5.0-1
mozillathunderbird>= 0 < 1:60.5.0-11:60.5.0-1
mozillathunderbird>= 0 < 1:60.5.1+build2-0ubuntu0.14.04.11:60.5.1+build2-0ubuntu0.14.04.1
mozillathunderbird>= 0 < 1:60.5.1+build2-0ubuntu0.16.04.11:60.5.1+build2-0ubuntu0.16.04.1
mozillathunderbird>= 0 < 1:60.5.1+build2-0ubuntu0.18.04.11:60.5.1+build2-0ubuntu0.18.04.1
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server

CVSS provenance

nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.