A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2018-10-18T13:00:00

Updated: 2024-08-05T08:30:59.980Z

Reserved: 2018-06-14T00:00:00

Link: CVE-2018-12365

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-10-18T13:29:02.400

Modified: 2018-12-03T20:09:20.063

Link: CVE-2018-12365

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-06-26T00:00:00Z

Links: CVE-2018-12365 - Bugzilla