CLD-570 Details
Other IDs this deficiency may be known by:
CVE ID |
None |
Other ID(s) |
fixed-in-60.2.1, mfsa2018-25 |
Basic Information:
Affected Package(s) |
thunderbird |
Deficiency Type |
SECURITY |
Date Created |
2018-10-04 16:03:06 |
Date Last Modified |
2018-10-06 12:16:37 |
Version Specific Information:
Cucumber 1.0 i686 | fixed in thunderbird-60.2.1-i686-1 |
Cucumber 1.0 x86_64 | fixed in thunderbird-60.2.1-x86_64-1 |
Cucumber 1.1 i686 |
fixed in thunderbird-60.2.1-i686-1 |
Cucumber 1.1 x86_64 |
fixed in thunderbird-60.2.1-x86_64-1 |
Details:
Fixes several CVEs:
CVE-2018-12377: Use-after-free in refresh driver timers
CVE-2018-12378: Use-after-free in IndexedDB
CVE-2018-12379: Out-of-bounds write with malicious MAR file
CVE-2017-16541: Proxy bypass using automount and autofs
CVE-2018-12376: Memory safety bugs fixed in Firefox 62 and Firefox ESR 60.2
CVE-2018-12385: Crash in TransportSecurityInfo due to cached data
CVE-2018-12383: Setting a master password post-Firefox 58 does not delete
unencrypted previously stored passwords
For more information see:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-25/