Lucene search

K
ubuntuUbuntuUSN-3778-1
HistoryOct 03, 2018 - 12:00 a.m.

Firefox vulnerabilities

2018-10-0300:00:00
ubuntu.com
186

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

9 High

AI Score

Confidence

High

0.449 Medium

EPSS

Percentile

97.4%

Releases

  • Ubuntu 18.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 14.04 ESM

Packages

  • firefox - Mozilla Open Source web browser

Details

A crash was discovered in TransportSecurityInfo used for SSL, which could
be triggered by data stored in the local cache directory. An attacker
could potentially exploit this in combination with another vulnerability
that allowed them to write data to the cache, to execute arbitrary code.
(CVE-2018-12385)

A type confusion bug was discovered in JavaScript. If a user were tricked
in to opening a specially crafted website, an attacker could exploit this
to cause a denial of service, or execute arbitrary code. (CVE-2018-12386)

It was discovered that the Array.prototype.push could leak memory
addresses to the calling function in some circumstances. An attacker could
exploit this in combination with another vulnerability to help execute
arbitrary code. (CVE-2018-12387)

OSVersionArchitecturePackageVersionFilename
Ubuntu18.04noarchfirefox< 62.0.3+build1-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchfirefox-dbg< 62.0.3+build1-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchfirefox-dev< 62.0.3+build1-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchfirefox-globalmenu< 62.0.3+build1-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchfirefox-locale-af< 62.0.3+build1-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchfirefox-locale-an< 62.0.3+build1-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchfirefox-locale-ar< 62.0.3+build1-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchfirefox-locale-as< 62.0.3+build1-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchfirefox-locale-ast< 62.0.3+build1-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchfirefox-locale-az< 62.0.3+build1-0ubuntu0.18.04.1UNKNOWN
Rows per page:
1-10 of 2961

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

9 High

AI Score

Confidence

High

0.449 Medium

EPSS

Percentile

97.4%