CLD-570 Details

Other IDs this deficiency may be known by:

CVE ID None
Other ID(s) fixed-in-60.2.1, mfsa2018-25

Basic Information:

Affected Package(s) thunderbird
Deficiency Type SECURITY
Date Created 2018-10-04 16:03:06
Date Last Modified 2018-10-06 12:16:37

Version Specific Information:

Cucumber 1.0 i686fixed in thunderbird-60.2.1-i686-1
Cucumber 1.0 x86_64fixed in thunderbird-60.2.1-x86_64-1

Cucumber 1.1 i686 fixed in thunderbird-60.2.1-i686-1
Cucumber 1.1 x86_64 fixed in thunderbird-60.2.1-x86_64-1

Details:

Fixes several CVEs:

CVE-2018-12377: Use-after-free in refresh driver timers
CVE-2018-12378: Use-after-free in IndexedDB
CVE-2018-12379: Out-of-bounds write with malicious MAR file
CVE-2017-16541: Proxy bypass using automount and autofs
CVE-2018-12376: Memory safety bugs fixed in Firefox 62 and Firefox ESR 60.2
CVE-2018-12385: Crash in TransportSecurityInfo due to cached data
CVE-2018-12383: Setting a master password post-Firefox 58 does not delete
	unencrypted previously stored passwords

For more information see:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-25/