PT-2018-2993 · Google+6 · Skia+7
Ivan Fratric
·
Published
2018-05-09
·
Updated
2024-12-12
·
CVE-2018-5159
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Thunderbird versions prior to 52.8
Thunderbird ESR versions prior to 52.8
Firefox versions prior to 60
Firefox ESR versions prior to 52.8
Description
The issue is related to an integer overflow in the Skia library, which can cause out-of-bounds writes due to the use of 32-bit integers in an array without proper overflow checks. This could lead to a crash that can be triggered by web content, potentially allowing remote code execution.
Recommendations
For Thunderbird versions prior to 52.8, update to version 52.8 or later.
For Thunderbird ESR versions prior to 52.8, update to version 52.8 or later.
For Firefox versions prior to 60, update to version 60 or later.
For Firefox ESR versions prior to 52.8, update to version 52.8 or later.
Exploit
Fix
Buffer Overflow
Memory Corruption
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Firefox
Red Hat
Skia
Suse
Thunderbird
Ubuntu