Name | CVE-2018-12363 |
Description | A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node being freed but the node still having a pointer referencing it. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-1406-1, DLA-1425-1, DSA-4235-1, DSA-4244-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
firefox (PTS) | sid | 131.0-1 | fixed |
firefox-esr (PTS) | jessie, jessie (lts) | 68.9.0esr-1~deb8u2 | fixed |
stretch (security), stretch (lts), stretch | 91.11.0esr-1~deb9u1 | fixed | |
buster (security), buster, buster (lts) | 115.12.0esr-1~deb10u1 | fixed | |
bullseye | 115.14.0esr-1~deb11u1 | fixed | |
bullseye (security) | 115.15.0esr-1~deb11u1 | fixed | |
bookworm | 115.14.0esr-1~deb12u1 | fixed | |
bookworm (security) | 115.15.0esr-1~deb12u1 | fixed | |
trixie | 115.15.0esr-1 | fixed | |
sid | 128.3.0esr-1 | fixed | |
thunderbird (PTS) | jessie, jessie (lts) | 1:68.9.0-1~deb8u2 | fixed |
stretch (security), stretch (lts), stretch | 1:91.10.0-1~deb9u1 | fixed | |
buster (security), buster, buster (lts) | 1:115.12.0-1~deb10u1 | fixed | |
bullseye | 1:115.12.0-1~deb11u1 | fixed | |
bullseye (security) | 1:115.15.0-1~deb11u1 | fixed | |
bookworm | 1:115.12.0-1~deb12u1 | fixed | |
bookworm (security) | 1:115.15.0-1~deb12u1 | fixed | |
trixie | 1:128.2.0esr-1 | fixed | |
sid | 1:128.2.3esr-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
firefox | source | (unstable) | 61.0-1 | |||
firefox-esr | source | wheezy | (unfixed) | end-of-life | ||
firefox-esr | source | jessie | 52.9.0esr-1~deb8u1 | DLA-1406-1 | ||
firefox-esr | source | stretch | 52.9.0esr-1~deb9u1 | DSA-4235-1 | ||
firefox-esr | source | (unstable) | 52.9.0esr-1 | |||
thunderbird | source | wheezy | (unfixed) | end-of-life | ||
thunderbird | source | jessie | 1:52.9.1-1~deb8u1 | DLA-1425-1 | ||
thunderbird | source | stretch | 1:52.9.1-1~deb9u1 | DSA-4244-1 | ||
thunderbird | source | (unstable) | 1:52.9.0-1 |
https://www.mozilla.org/en-US/security/advisories/mfsa2018-15/#CVE-2018-12363
https://www.mozilla.org/en-US/security/advisories/mfsa2018-17/#CVE-2018-12363
https://www.mozilla.org/en-US/security/advisories/mfsa2018-18/#CVE-2018-12363