CVE-2018-18505

An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00021.html
http://www.securityfocus.com/bid/106781 Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2019:0218 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0219 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0269 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0270 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1087565 Issue Tracking Patch Vendor Advisory
https://lists.debian.org/debian-lts-announce/2019/01/msg00025.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/02/msg00024.html Mailing List Third Party Advisory
https://security.gentoo.org/glsa/201903-04 Third Party Advisory
https://security.gentoo.org/glsa/201904-07 Third Party Advisory
https://usn.ubuntu.com/3874-1/ Third Party Advisory
https://usn.ubuntu.com/3897-1/ Third Party Advisory
https://www.debian.org/security/2019/dsa-4376 Third Party Advisory
https://www.debian.org/security/2019/dsa-4392 Third Party Advisory
https://www.mozilla.org/security/advisories/mfsa2019-01/ Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2019-02/ Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2019-03/ Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00021.html
http://www.securityfocus.com/bid/106781 Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2019:0218 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0219 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0269 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:0270 Third Party Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1087565 Issue Tracking Patch Vendor Advisory
https://lists.debian.org/debian-lts-announce/2019/01/msg00025.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2019/02/msg00024.html Mailing List Third Party Advisory
https://security.gentoo.org/glsa/201903-04 Third Party Advisory
https://security.gentoo.org/glsa/201904-07 Third Party Advisory
https://usn.ubuntu.com/3874-1/ Third Party Advisory
https://usn.ubuntu.com/3897-1/ Third Party Advisory
https://www.debian.org/security/2019/dsa-4376 Third Party Advisory
https://www.debian.org/security/2019/dsa-4392 Third Party Advisory
https://www.mozilla.org/security/advisories/mfsa2019-01/ Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2019-02/ Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2019-03/ Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-02-05 21:29

Updated : 2024-11-21 03:56


NVD link : CVE-2018-18505

Mitre link : CVE-2018-18505

CVE.ORG link : CVE-2018-18505


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
  • firefox_esr

redhat

  • enterprise_linux_workstation
  • enterprise_linux_server_aus
  • enterprise_linux_server_eus
  • enterprise_linux_desktop
  • enterprise_linux_server
  • enterprise_linux_server_tus

debian

  • debian_linux

canonical

  • ubuntu_linux
CWE
CWE-287

Improper Authentication