CVE-2018-12393
CVE-2018-12393
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 3.9%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
28 feb 2019Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit builds are not vulnerable to this issue.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://access.redhat.com/errata/RHSA-2018:3005https://access.redhat.com/errata/RHSA-2018:3006https://access.redhat.com/errata/RHSA-2018:3531https://access.redhat.com/errata/RHSA-2018:3532https://bugzilla.mozilla.org/show_bug.cgi?id=1495011https://lists.debian.org/debian-lts-announce/2018/11/msg00008.htmlhttps://lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlhttps://security.gentoo.org/glsa/201811-04https://security.gentoo.org/glsa/201811-13https://usn.ubuntu.com/3801-1/https://usn.ubuntu.com/3868-1/https://www.debian.org/security/2018/dsa-4324