Memory leak in Mozilla Thunderbird - CVE-2018-12374

 

Memory leak in Mozilla Thunderbird - CVE-2018-12374

Published: July 4, 2018


Vulnerability identifier: #VU13556
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12374
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists due to plaintext of decrypted emails can leak through. A remote attacker can submit an embedded form by press enter key within a text input field, submit an embedded form, trigger memory leak and gain access to arbitrary data.


Affected software

Mozilla Thunderbird
Gentoo Linux
Debian Linux
Arch Linux
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for ARM
SUSE Linux
Slackware Linux
Opensuse

How to mitigate CVE-2018-12374

Update to version 59.2.


External References

Related Security Bulletins