CVE-2018-12367

CVSS v3.0 4.3 (Medium)
43% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.50 % (77th)
0.50% Progress
Affected Products 5
Advisories 12

In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted but it was found that it could be used as a precision timer. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.

Weaknesses
CWE-20
Improper Input Validation
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2018-10-18 13:29:03
(6 years ago)
Updated Date
2018-12-06 15:10:55
(5 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0

Configuration #2

    CPE23 From Up To
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts
  Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts
  Canonical Ubuntu Linux 17.10 cpe:2.3:o:canonical:ubuntu_linux:17.10
  Canonical Ubuntu Linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts

Configuration #3

    CPE23 From Up To
  Mozilla Firefox prior 61.0 version cpe:2.3:a:mozilla:firefox < 61.0
  Mozilla Firefox Esr prior 60.1.0 version cpe:2.3:a:mozilla:firefox_esr < 60.1.0
  Mozilla Thunderbird prior 60.0 version cpe:2.3:a:mozilla:thunderbird < 60.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...