SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-12367

This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.

MEDIUM 4.3EPSS 1.98%

Does this matter?

Lower severity and a low EPSS score (1.98%). Track it; it rarely justifies an emergency change on its own.

Description

In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted but it was found that it could be used as a precision timer. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.

CVSS 3.0
4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS
1.98% probability · 79th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
debian/debian linux · canonical/ubuntu linux · mozilla/firefox · mozilla/thunderbird
Source
security@mozilla.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.