Memory leak in Mozilla Thunderbird - CVE-2018-12373

 

Memory leak in Mozilla Thunderbird - CVE-2018-12373

Published: July 4, 2018


Vulnerability identifier: #VU13555
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12373
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists due to dDecrypted S/MIME parts hidden with CSS or <plaintext> can leak plaintext when included in a HTML reply/forward. A remote attacker can trigger memory leak and gain access to arbitrary data.


Affected software

Mozilla Thunderbird
Gentoo Linux
Debian Linux
Arch Linux
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for ARM
SUSE Linux
Slackware Linux
Opensuse

How to mitigate CVE-2018-12373

Update to version 59.2.


External References

Related Security Bulletins