ZeroHour

CVE-2018-5159

PoC
CVSS 3.0
9.8 critical
EPSS
21%p97
Published
()
Modified
Description

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

Vendors
debianredhatmozillacanonical
Products
debian linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, firefox, thunderbird, thunderbird esr, ubuntu linux
Weakness
CWE-190, CWE-787
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.