High severity7.0NVD Advisory· Published Oct 18, 2018· Updated Jun 17, 2026
CVE-2018-12385
CVE-2018-12385
Description
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
98cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <62.0.2
- cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*range: <60.2.1
- (no CPE)range: <60.2.1
- (no CPE)range: unspecified
- (no CPE)range: unspecified
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*range: <60.2.1
- (no CPE)range: <60.2.1
- (no CPE)range: unspecified
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
- osv-coords75 versionspkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/apache2-mod_nss&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/apache2-mod_nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/apache2-mod_nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/apache2-mod_nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/apache2-mod_nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/apache2-mod_nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/apache2-mod_nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/apache2-mod_nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/apache2-mod_nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/apache2-mod_nss&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/mozilla-nspr&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/mozilla-nspr&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/mozilla-nss&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/mozilla-nss&distro=SUSE%20OpenStack%20Cloud%207
< 92.0-1.2+ 74 more
- (no CPE)range: < 92.0-1.2
- (no CPE)range: < 91.1.1-1.1
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2-3.13.3
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60.2.2esr-109.46.1
- (no CPE)range: < 60-32.3.1
- (no CPE)range: < 60-32.3.1
- (no CPE)range: < 60-32.3.1
- (no CPE)range: < 60-4.5.3
- (no CPE)range: < 60-32.3.1
- (no CPE)range: < 60-32.3.1
- (no CPE)range: < 60-32.3.1
- (no CPE)range: < 60-32.3.1
- (no CPE)range: < 60-32.3.1
- (no CPE)range: < 60-32.3.1
- (no CPE)range: < 60-32.3.1
- (no CPE)range: < 60-32.3.1
- (no CPE)range: < 60-32.3.1
- (no CPE)range: < 60-32.3.1
- (no CPE)range: < 60.2.1-3.13.1
- (no CPE)range: < 60.3.0-74.2
- (no CPE)range: < 1.0.14-19.6.3
- (no CPE)range: < 1.0.14-19.6.3
- (no CPE)range: < 1.0.14-19.6.3
- (no CPE)range: < 1.0.14-19.6.3
- (no CPE)range: < 1.0.14-19.6.3
- (no CPE)range: < 1.0.14-19.6.3
- (no CPE)range: < 1.0.14-19.6.3
- (no CPE)range: < 1.0.14-19.6.3
- (no CPE)range: < 1.0.14-19.6.3
- (no CPE)range: < 1.0.14-19.6.3
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 4.19-19.3.1
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
- (no CPE)range: < 3.36.4-58.15.3
Patches
Vulnerability mechanics
References
18- www.securityfocus.com/bid/105380nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1041700nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1041701nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2018:2834nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2018:2835nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2018:3403nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2018:3458nvdThird Party Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions RequiredVendor Advisory
- lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/201810-01nvdThird Party Advisory
- security.gentoo.org/glsa/201811-13nvdThird Party Advisory
- usn.ubuntu.com/3778-1/nvdThird Party Advisory
- usn.ubuntu.com/3793-1/nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4304nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4327nvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2018-22/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2018-23/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2018-25/nvdVendor Advisory
News mentions
0No linked articles in our index yet.