Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5159

Опубликовано: 11 июн. 2018
Источник: debian
EPSS Средний

Описание

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed60.0-1package
firefox-esrfixed52.8.0esr-1package
thunderbirdfixed1:52.8.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/#CVE-2018-5159

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5159

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/#CVE-2018-5159

EPSS

Процентиль: 97%
0.37556
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 9.8
redhat
почти 8 лет назад

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 9.8
nvd
почти 8 лет назад

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 9.8
github
почти 4 года назад

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 7.5
fstec
почти 8 лет назад

Уязвимость библиотеки Skia браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 97%
0.37556
Средний