Bug 1110507 - (CVE-2018-12387) VUL-0: CVE-2018-12387: MozillaFirefox: Array.prototype.push stack pointer vulnerability
(CVE-2018-12387)
VUL-0: CVE-2018-12387: MozillaFirefox: Array.prototype.push stack pointer vul...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/216080/
CVSSv2:NVD:CVE-2018-12387:6.4:(AV:N/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-10-02 21:14 UTC by Andreas Stieger
Modified: 2022-09-06 16:40 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2018-10-02 21:14:57 UTC
CVE-2018-12387:
Reporter:  Bruno Keith, Niklas Baumstark via Beyond Security’s SecuriTeam Secure Disclosure program
Impact: critical
Description : A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process.

Fixed in

        Firefox 62.0.3
        Firefox ESR 60.2.2

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-12387
https://www.mozilla.org/en-US/security/advisories/mfsa2018-24/#CVE-2018-12387
https://bugzilla.mozilla.org/show_bug.cgi?id=1493903
Comment 1 Swamp Workflow Management 2018-10-03 04:00:10 UTC
This is an autogenerated message for OBS integration:
This bug (1110507) was mentioned in
https://build.opensuse.org/request/show/639667 15.0+42.3 / MozillaFirefox
Comment 2 Swamp Workflow Management 2018-10-04 13:10:28 UTC
openSUSE-SU-2018:2996-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1110506,1110507
CVE References: CVE-2018-12386,CVE-2018-12387
Sources used:
openSUSE Leap 42.3 (src):    MozillaFirefox-60.2.2-118.1
openSUSE Leap 15.0 (src):    MozillaFirefox-60.2.2-lp150.3.23.1
Comment 3 Swamp Workflow Management 2018-10-04 19:00:52 UTC
This is an autogenerated message for OBS integration:
This bug (1110507) was mentioned in
https://build.opensuse.org/request/show/640013 15.0+42.3 / MozillaThunderbird
Comment 7 Swamp Workflow Management 2018-10-25 22:17:34 UTC
SUSE-SU-2018:3476-1: An update that solves four vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1094767,1107343,1109363,1109465,1110506,1110507
CVE References: CVE-2018-12383,CVE-2018-12385,CVE-2018-12386,CVE-2018-12387
Sources used:
SUSE Linux Enterprise Module for Desktop Applications 15 (src):    MozillaFirefox-60.2.2-3.13.3, MozillaFirefox-branding-SLE-60-4.5.3
Comment 8 Swamp Workflow Management 2018-10-31 17:30:31 UTC
SUSE-SU-2018:3591-1: An update that solves 10 vulnerabilities and has 17 fixes is now available.

Category: security (important)
Bug References: 1012260,1021577,1026191,1041469,1041894,1049703,1061204,1064786,1065464,1066489,1073210,1078436,1091551,1092697,1094767,1096515,1107343,1108771,1108986,1109363,1109465,1110506,1110507,703591,839074,857131,893359
CVE References: CVE-2017-16541,CVE-2018-12376,CVE-2018-12377,CVE-2018-12378,CVE-2018-12379,CVE-2018-12381,CVE-2018-12383,CVE-2018-12385,CVE-2018-12386,CVE-2018-12387
Sources used:
SUSE OpenStack Cloud 7 (src):    MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    MozillaFirefox-60.2.2esr-109.46.1, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
SUSE Linux Enterprise Server 12-SP3 (src):    MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
SUSE Linux Enterprise Server 12-LTSS (src):    MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
SUSE Linux Enterprise Desktop 12-SP3 (src):    MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
SUSE Enterprise Storage 4 (src):    MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
SUSE CaaS Platform ALL (src):    mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
SUSE CaaS Platform 3.0 (src):    mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
Comment 9 Swamp Workflow Management 2018-12-05 14:24:09 UTC
SUSE-SU-2018:3591-2: An update that solves 10 vulnerabilities and has 17 fixes is now available.

Category: security (important)
Bug References: 1012260,1021577,1026191,1041469,1041894,1049703,1061204,1064786,1065464,1066489,1073210,1078436,1091551,1092697,1094767,1096515,1107343,1108771,1108986,1109363,1109465,1110506,1110507,703591,839074,857131,893359
CVE References: CVE-2017-16541,CVE-2018-12376,CVE-2018-12377,CVE-2018-12378,CVE-2018-12379,CVE-2018-12381,CVE-2018-12383,CVE-2018-12385,CVE-2018-12386,CVE-2018-12387
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    MozillaFirefox-60.2.2esr-109.46.1, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
SUSE Linux Enterprise Server 12-SP4 (src):    MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
SUSE Linux Enterprise Desktop 12-SP4 (src):    MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
Comment 10 Scott Reeves 2019-02-27 00:19:46 UTC
Fix released.
Comment 13 Marcus Meissner 2019-07-18 07:18:54 UTC
done