CVE-2018-12371
Summary
| CVE | CVE-2018-12371 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-09 14:15:00 UTC |
| Updated | 2020-07-13 02:41:00 UTC |
| Description | An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security vulnerabilities fixed in Firefox ESR 60.1 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| 1465686 - (CVE-2018-12371) Heap overflow write in SkEdgeBuilder::buildPoly |
MISC |
bugzilla.mozilla.org |
Exploit, Issue Tracking, Patch, Vendor Advisory |
| Security vulnerabilities fixed in Thunderbird 60 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| Security vulnerabilities fixed in Firefox 61 — Mozilla |
MISC |
www.mozilla.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710279 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 201810-01)
- 710285 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 201811-13)