PT-2018-2993 · Google+6 · Skia+7
Ivan Fratric
·
Publicado
2018-05-09
·
Atualizado
2024-12-12
·
CVE-2018-5159
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Thunderbird versions prior to 52.8
Thunderbird ESR versions prior to 52.8
Firefox versions prior to 60
Firefox ESR versions prior to 52.8
Description
The issue is related to an integer overflow in the Skia library, which can cause out-of-bounds writes due to the use of 32-bit integers in an array without proper overflow checks. This could lead to a crash that can be triggered by web content, potentially allowing remote code execution.
Recommendations
For Thunderbird versions prior to 52.8, update to version 52.8 or later.
For Thunderbird ESR versions prior to 52.8, update to version 52.8 or later.
For Firefox versions prior to 60, update to version 60 or later.
For Firefox ESR versions prior to 52.8, update to version 52.8 or later.
Exploit
Correção
Buffer Overflow
Memory Corruption
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Firefox
Red Hat
Skia
Suse
Thunderbird
Ubuntu