Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5159

Опубликовано: 11 июн. 2018
Источник: debian

Описание

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed60.0-1package
firefox-esrfixed52.8.0esr-1package
thunderbirdfixed1:52.8.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/#CVE-2018-5159

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5159

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/#CVE-2018-5159

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 9.8
redhat
больше 7 лет назад

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 9.8
nvd
больше 7 лет назад

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 9.8
github
больше 3 лет назад

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость библиотеки Skia браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, позволяющая нарушителю выполнить произвольный код