Bugzilla – Bug 1109363
VUL-0: CVE-2018-12385: MozillaFirefox: Crash in TransportSecurityInfo due to cached data
Last modified: 2022-09-06 16:40:27 UTC
https://www.mozilla.org/en-US/security/advisories/mfsa2018-23/#CVE-2018-12385 CVE-2018-12385: Crash in TransportSecurityInfo due to cached data A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacher to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. Fixed in Firefox ESR 60.2.1, Firefox 62.0.2 https://bugzilla.mozilla.org/show_bug.cgi?id=1490585
This is an autogenerated message for OBS integration: This bug (1109363) was mentioned in https://build.opensuse.org/request/show/637109 15.0+42.3 / MozillaFirefox
openSUSE-SU-2018:2817-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1107343,1109363 CVE References: CVE-2018-12383,CVE-2018-12385 Sources used: openSUSE Leap 42.3 (src): MozillaFirefox-60.2.1-112.1 openSUSE Leap 15.0 (src): MozillaFirefox-60.2.1-lp150.3.17.1
This is an autogenerated message for OBS integration: This bug (1109363) was mentioned in https://build.opensuse.org/request/show/637781 Factory / MozillaFirefox
This is an autogenerated message for OBS integration: This bug (1109363) was mentioned in https://build.opensuse.org/request/show/640013 15.0+42.3 / MozillaThunderbird
This is an autogenerated message for OBS integration: This bug (1109363) was mentioned in https://build.opensuse.org/request/show/640041 15.0+42.3 / MozillaThunderbird
openSUSE-SU-2018:3051-1: An update that fixes 20 vulnerabilities is now available. Category: security (important) Bug References: 1066489,1084603,1098998,1107343,1107772,1109363,1109379 CVE References: CVE-2017-16541,CVE-2018-12359,CVE-2018-12360,CVE-2018-12361,CVE-2018-12362,CVE-2018-12363,CVE-2018-12364,CVE-2018-12365,CVE-2018-12366,CVE-2018-12367,CVE-2018-12371,CVE-2018-12376,CVE-2018-12377,CVE-2018-12378,CVE-2018-12383,CVE-2018-12385,CVE-2018-16541,CVE-2018-5156,CVE-2018-5187,CVE-2018-5188 Sources used: openSUSE Leap 42.3 (src): MozillaThunderbird-60.2.1-77.2 openSUSE Leap 15.0 (src): MozillaThunderbird-60.2.1-lp150.3.19.1
SUSE-SU-2018:3247-1: An update that fixes 19 vulnerabilities is now available. Category: security (important) Bug References: 1066489,1084603,1098998,1107343,1107772,1109363,1109379 CVE References: CVE-2017-16541,CVE-2018-12359,CVE-2018-12360,CVE-2018-12361,CVE-2018-12362,CVE-2018-12363,CVE-2018-12364,CVE-2018-12365,CVE-2018-12366,CVE-2018-12367,CVE-2018-12371,CVE-2018-12376,CVE-2018-12377,CVE-2018-12378,CVE-2018-12383,CVE-2018-12385,CVE-2018-5156,CVE-2018-5187,CVE-2018-5188 Sources used: SUSE Linux Enterprise Workstation Extension 15 (src): MozillaThunderbird-60.2.1-3.13.1
SUSE-SU-2018:3476-1: An update that solves four vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1094767,1107343,1109363,1109465,1110506,1110507 CVE References: CVE-2018-12383,CVE-2018-12385,CVE-2018-12386,CVE-2018-12387 Sources used: SUSE Linux Enterprise Module for Desktop Applications 15 (src): MozillaFirefox-60.2.2-3.13.3, MozillaFirefox-branding-SLE-60-4.5.3
SUSE-SU-2018:3591-1: An update that solves 10 vulnerabilities and has 17 fixes is now available. Category: security (important) Bug References: 1012260,1021577,1026191,1041469,1041894,1049703,1061204,1064786,1065464,1066489,1073210,1078436,1091551,1092697,1094767,1096515,1107343,1108771,1108986,1109363,1109465,1110506,1110507,703591,839074,857131,893359 CVE References: CVE-2017-16541,CVE-2018-12376,CVE-2018-12377,CVE-2018-12378,CVE-2018-12379,CVE-2018-12381,CVE-2018-12383,CVE-2018-12385,CVE-2018-12386,CVE-2018-12387 Sources used: SUSE OpenStack Cloud 7 (src): MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3 SUSE Linux Enterprise Software Development Kit 12-SP3 (src): MozillaFirefox-60.2.2esr-109.46.1, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3 SUSE Linux Enterprise Server for SAP 12-SP2 (src): MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3 SUSE Linux Enterprise Server for SAP 12-SP1 (src): MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3 SUSE Linux Enterprise Server 12-SP3 (src): MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3 SUSE Linux Enterprise Server 12-SP2-LTSS (src): MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3 SUSE Linux Enterprise Server 12-SP1-LTSS (src): MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3 SUSE Linux Enterprise Server 12-LTSS (src): MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3 SUSE Linux Enterprise Desktop 12-SP3 (src): MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3 SUSE Enterprise Storage 4 (src): MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3 SUSE CaaS Platform ALL (src): mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3 SUSE CaaS Platform 3.0 (src): mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
openSUSE-SU-2018:3687-1: An update that fixes 25 vulnerabilities is now available. Category: security (important) Bug References: 1066489,1084603,1098998,1107343,1107772,1109363,1109379,1112852 CVE References: CVE-2017-16541,CVE-2018-12359,CVE-2018-12360,CVE-2018-12361,CVE-2018-12362,CVE-2018-12363,CVE-2018-12364,CVE-2018-12365,CVE-2018-12366,CVE-2018-12367,CVE-2018-12371,CVE-2018-12376,CVE-2018-12377,CVE-2018-12378,CVE-2018-12383,CVE-2018-12385,CVE-2018-12389,CVE-2018-12390,CVE-2018-12391,CVE-2018-12392,CVE-2018-12393,CVE-2018-16541,CVE-2018-5156,CVE-2018-5187,CVE-2018-5188 Sources used: SUSE Package Hub for SUSE Linux Enterprise 12 (src): MozillaThunderbird-60.3.0-74.2
SUSE-SU-2018:3591-2: An update that solves 10 vulnerabilities and has 17 fixes is now available. Category: security (important) Bug References: 1012260,1021577,1026191,1041469,1041894,1049703,1061204,1064786,1065464,1066489,1073210,1078436,1091551,1092697,1094767,1096515,1107343,1108771,1108986,1109363,1109465,1110506,1110507,703591,839074,857131,893359 CVE References: CVE-2017-16541,CVE-2018-12376,CVE-2018-12377,CVE-2018-12378,CVE-2018-12379,CVE-2018-12381,CVE-2018-12383,CVE-2018-12385,CVE-2018-12386,CVE-2018-12387 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP4 (src): MozillaFirefox-60.2.2esr-109.46.1, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3 SUSE Linux Enterprise Server 12-SP4 (src): MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, apache2-mod_nss-1.0.14-19.6.3, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3 SUSE Linux Enterprise Desktop 12-SP4 (src): MozillaFirefox-60.2.2esr-109.46.1, MozillaFirefox-branding-SLE-60-32.3.1, mozilla-nspr-4.19-19.3.1, mozilla-nss-3.36.4-58.15.3
Fix released.
done