Learn about CVE-2018-12385, a vulnerability in Thunderbird and Firefox that triggers a crash in SSL functionality due to cached data. Find out how to mitigate this issue and protect your systems.
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.
Understanding CVE-2018-12385
This CVE involves a crash in TransportSecurityInfo due to cached data.
What is CVE-2018-12385?
The vulnerability allows for a crash in TransportSecurityInfo due to data stored in the local cache, impacting Thunderbird, Firefox ESR, and Firefox.
The Impact of CVE-2018-12385
The vulnerability can lead to a crash in SSL functionality, potentially triggered by malicious data stored in the local cache.
Technical Details of CVE-2018-12385
This section provides more technical insights into the CVE.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from the CVE is crucial.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates