CLD-560 Details

Other IDs this deficiency may be known by:

CVE ID None
Other ID(s) fixed-in-60.2.1

Basic Information:

Affected Package(s) firefox
Deficiency Type SECURITY
Date Created 2018-09-23 11:07:07
Date Last Modified 2018-09-23 11:13:16

Version Specific Information:

Cucumber 1.0 i686fixed in firefox-60.2.1esr-i686-1
Cucumber 1.0 x86_64fixed in firefox-60.2.1esr-x86_64-1

Cucumber 1.1 i686 fixed in firefox-60.2.1esr-i686-1
Cucumber 1.1 x86_64 fixed in firefox-60.2.1esr-x86_64-1

Details:

This update to Firefox 60.2.1 fixes the following vulnerabilities:

CVE-2018-12385: Crash in TransportSecurityInfo due to cached data
CVE-2018-12383: Setting a master password post-Firefox 58 does not delete
	unencrypted previously stored passwords

One of these is listed as being of moderate severity, the other is low severity.
For more information see
https://www.mozilla.org/en-US/security/advisories/mfsa2018-23/