CVE-2018-12378
CVE-2018-12378
A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://access.redhat.com/errata/RHSA-2018:2692https://access.redhat.com/errata/RHSA-2018:2693https://access.redhat.com/errata/RHSA-2018:3403https://access.redhat.com/errata/RHSA-2018:3458https://bugzilla.mozilla.org/show_bug.cgi?id=1459383https://lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlhttps://security.gentoo.org/glsa/201810-01https://security.gentoo.org/glsa/201811-13https://usn.ubuntu.com/3761-1/https://usn.ubuntu.com/3793-1/https://www.debian.org/security/2018/dsa-4287https://www.debian.org/security/2018/dsa-4327