CVE-2018-12365
Last modified
CVE-2018-12365 is a vulnerability of currently unknown severity. A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. EPSS estimates a 3.16% chance of exploitation in the next 30 days.
Description
A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.6 |
| Redhat | Enterprise Linux Server Eus | 7.5 |
| Redhat | Enterprise Linux Server Eus | 7.6 |
| Redhat | Enterprise Linux Server Tus | 7.6 |
| Redhat | Enterprise Linux Workstation | 6.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 17.10 |
| Canonical | Ubuntu Linux | 18.04 |
| Mozilla | Firefox | < 61.0 |
| Mozilla | Firefox | >= 53.0, < 60.1.0 |
| Mozilla | Firefox Esr | < 52.9 |
| Mozilla | Thunderbird | < 52.9 |
| Mozilla | Thunderbird | >= 52.9.1, < 60.0 |
References
- http://www.securityfocus.com/bid/104560Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041193Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2112Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2113Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2251Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2252Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1459206Issue Tracking, Permissions Required, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/06/msg00014.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00013.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201810-01Third Party Advisory
- https://security.gentoo.org/glsa/201811-13Third Party Advisory
- https://usn.ubuntu.com/3705-1/Third Party Advisory
- https://usn.ubuntu.com/3714-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4235Third Party Advisory
- https://www.debian.org/security/2018/dsa-4244Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-15/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-16/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-17/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-18/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-19/Vendor Advisory
- http://www.securityfocus.com/bid/104560Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041193Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2112Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2113Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2251Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2252Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1459206Issue Tracking, Permissions Required, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/06/msg00014.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00013.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201810-01Third Party Advisory
- https://security.gentoo.org/glsa/201811-13Third Party Advisory
- https://usn.ubuntu.com/3705-1/Third Party Advisory
- https://usn.ubuntu.com/3714-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4235Third Party Advisory
- https://www.debian.org/security/2018/dsa-4244Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-15/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-16/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-17/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-18/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-19/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12365?
How severe is CVE-2018-12365?
How do I fix CVE-2018-12365?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1236Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-12360A use-after-free vulnerability can occur when deleting an in…
- CVE-2018-12361An integer overflow can occur in the SwizzleData code while …
- CVE-2018-12362An integer overflow can occur during graphics operations don…
- CVE-2018-12363A use-after-free vulnerability can occur when script uses mu…
- CVE-2018-12364NPAPI plugins, such as Adobe Flash, can send non-simple cros…
- CVE-2018-12366An invalid grid size during QCMS (color profile) transformat…
- CVE-2018-12367In the previous mitigations for Spectre, the resolution or p…
- CVE-2018-12368Windows 10 does not warn users before opening executable fil…
- CVE-2018-12369WebExtensions bundled with embedded experiments were not cor…
- CVE-2018-1237Dell EMC ScaleIO versions prior to 2.5, contain improper res…
- CVE-2018-12370In Reader View SameSite cookie protections are not checked o…
Are you affected by CVE-2018-12365?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
