ZeroHour

CVE-2018-12366

CVSS 3.0
6.5 medium
EPSS
3%p87
Published
()
Modified
Description

An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private data into the output. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

Vendors
redhatdebiancanonicalmozilla
Products
enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, debian linux, ubuntu linux, firefox, firefox esr, thunderbird
Weakness
CWE-125
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.