Memory leak in Mozilla Thunderbird - CVE-2018-12372
Published: July 4, 2018
Vulnerability identifier: #VU13554
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12372
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists due to decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. A remote attacker can trigger memory leak and gain access to arbitrary data.
Affected software
Mozilla Thunderbird
Gentoo Linux
Debian Linux
Arch Linux
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for ARM
SUSE Linux
Slackware Linux
Opensuse
Gentoo Linux
Debian Linux
Arch Linux
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for ARM
SUSE Linux
Slackware Linux
Opensuse
How to mitigate CVE-2018-12372
Update to version 59.2.
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Thunderbird
- Slackware Linux update for mozilla-thunderbird
- SUSE Linux update for MozillaThunderbird
- OpenSUSE Linux update for Mozilla Thunderbird
- Debian update for thunderbird
- Arch Linux update for thunderbird
- Red Hat update for Mozilla Firefox
- Red Hat update for Mozilla Firefox
- Gentoo update for Mozilla Thunderbird