Vulnerability Description
An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 61.0 |
| Mozilla | Firefox Esr | < 60.1 |
| Mozilla | Thunderbird | < 60.0 |
| Debian | Debian Linux | 8.0 |
| Canonical | Ubuntu Linux | 14.04 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/104558Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041193Third Party AdvisoryVDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1463244Issue TrackingPermissions Required
- https://lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlThird Party Advisory
- https://security.gentoo.org/glsa/201810-01MitigationThird Party Advisory
- https://security.gentoo.org/glsa/201811-13MitigationThird Party Advisory
- https://usn.ubuntu.com/3705-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4295Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-15/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-16/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-19/Vendor Advisory
- http://www.securityfocus.com/bid/104558Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041193Third Party AdvisoryVDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1463244Issue TrackingPermissions Required
- https://lists.debian.org/debian-lts-announce/2018/11/msg00011.htmlThird Party Advisory
FAQ
What is CVE-2018-12361?
CVE-2018-12361 is a vulnerability with a CVSS score of 8.8 (HIGH). An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which result...
How severe is CVE-2018-12361?
CVE-2018-12361 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12361?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Firefox Esr, Mozilla Thunderbird, Debian Debian Linux, Canonical Ubuntu Linux.