Mozilla Firefox is vulnerable to denial of service (DoS) attacks. The vulnerability exists in an unknown code of the component Nested Event Handler when manipulating user events in nested loops while opening a document through script resulting an application crash due to poor event handling.
www.securityfocus.com/bid/105718
www.securityfocus.com/bid/105769
www.securitytracker.com/id/1041944
access.redhat.com/errata/RHSA-2018:3005
access.redhat.com/errata/RHSA-2018:3006
access.redhat.com/errata/RHSA-2018:3531
access.redhat.com/errata/RHSA-2018:3532
access.redhat.com/security/updates/classification/#critical
bugzilla.mozilla.org/show_bug.cgi?id=1492823
bugzilla.redhat.com/show_bug.cgi?id=1638082
lists.debian.org/debian-lts-announce/2018/11/msg00008.html
lists.debian.org/debian-lts-announce/2018/11/msg00011.html
security.gentoo.org/glsa/201811-04
security.gentoo.org/glsa/201811-13
usn.ubuntu.com/3801-1/
usn.ubuntu.com/3868-1/
www.debian.org/security/2018/dsa-4324
www.debian.org/security/2018/dsa-4337
www.mozilla.org/en-US/security/advisories/mfsa2018-27/
www.mozilla.org/security/advisories/mfsa2018-26/
www.mozilla.org/security/advisories/mfsa2018-27/
www.mozilla.org/security/advisories/mfsa2018-28/