CVE-2018-12377
CVE-2018-12377
A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://access.redhat.com/errata/RHSA-2018:2692https://access.redhat.com/errata/RHSA-2018:2693https://access.redhat.com/errata/RHSA-2018:3403https://access.redhat.com/errata/RHSA-2018:3458https://bugzilla.mozilla.org/show_bug.cgi?id=1470260https://lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlhttps://security.gentoo.org/glsa/201810-01https://security.gentoo.org/glsa/201811-13https://usn.ubuntu.com/3761-1/https://usn.ubuntu.com/3793-1/https://www.debian.org/security/2018/dsa-4287https://www.debian.org/security/2018/dsa-4327