Timing attack in Mozilla Firefox - CVE-2018-12367
Published: June 27, 2018
Vulnerability identifier: #VU13489
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12367
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to conduct timing attack.
The weakness exists due to in the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. A remote attacker can use PerformanceNavigationTiming as a precision timer and conduct timing attack and gain access to arbitrary data.
The weakness exists due to in the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. A remote attacker can use PerformanceNavigationTiming as a precision timer and conduct timing attack and gain access to arbitrary data.
Affected software
Mozilla Firefox
Firefox ESR
Arch Linux
Debian Linux
Gentoo Linux
Opensuse
openSUSE Leap
Mozilla Thunderbird
Firefox ESR
Arch Linux
Debian Linux
Gentoo Linux
Opensuse
openSUSE Leap
Mozilla Thunderbird
How to mitigate CVE-2018-12367
Update to version 61.0.
Mozilla Firefox - update to 61.0
Mozilla Thunderbird - update to 60.0
Mozilla Thunderbird - update to 60.0
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Mozilla Firefox ESR
- Arch Linux update for firefox
- OpenSUSE Linux update for MozillaFirefox
- Multiple vulnerabilities in Mozilla Thunderbird
- Arch Linux update for thunderbird
- OpenSUSE Linux update for MozillaThunderbird
- Debian update for thunderbird
- Gentoo update for Mozilla Firefox
- OpenSUSE Linux update for MozillaThunderbird
- Gentoo update for Mozilla Thunderbird
- OpenSUSE Linux update for MozillaThunderbird