SB2018070206 - Multiple vulnerabilities in Pale Moon



SB2018070206 - Multiple vulnerabilities in Pale Moon

Published: July 2, 2018 Updated: July 2, 2018

Security Bulletin ID SB2018070206
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Use-after-free error (CVE-ID: CVE-2018-12292)

The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code on the target system.

The weakness exists due to use-after-free error in DOMProxyHandler::EnsureExpandoObject. A remote unauthenticated attacker can trigger memory corruption and cause the service to crash or execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


2) Information disclosure (CVE-ID: CVE-2017-0381)

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability exists due to a flaw in silk/NLSF_stabilize.c in libopus in Mediaserver. A local attacker can run a specially crafted application to access data outside of its permission levels.


Remediation

Install update from vendor's website.