A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2018-24/#CVE-2018-12386
Acknowledgments: Name: the Mozilla project Upstream: Niklas Baumstark, Samuel Groß, Bruno Keith via Beyond Security's SecuriTeam Secure Disclosure program
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2018:2881 https://access.redhat.com/errata/RHSA-2018:2881
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2018:2884 https://access.redhat.com/errata/RHSA-2018:2884