Memory leak in Mozilla Thunderbird - CVE-2018-12372

 

Memory leak in Mozilla Thunderbird - CVE-2018-12372

Published: July 4, 2018


Vulnerability identifier: #VU13554
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12372
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists due to decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. A remote attacker can trigger memory leak and gain access to arbitrary data.


Affected software

Mozilla Thunderbird
Gentoo Linux
Debian Linux
Arch Linux
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for ARM
SUSE Linux
Slackware Linux
Opensuse

How to mitigate CVE-2018-12372

Update to version 59.2.


External References

Related Security Bulletins