CVE-2018-12386
firefox-esr - security update
8.1
HIGH
CVSS 3.1
EPSS 13.4%
Description
A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.
How to fix CVE-2018-12386
To remediate CVE-2018-12386, upgrade the affected package to a fixed version below.
- —upgrade to 60.2.2esr-1 or later
- —upgrade to 60.2.2esr-1~deb9u1 or later
Is CVE-2018-12386 being exploited?
Moderate — EPSS is 13.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 60.2.2esr-1
- from 0, < 60.2.2esr-1~deb9u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |