CVE-2018-12362Integer Overflow or Wraparound in Mozilla Firefox

Severity
8.8HIGHNVD
EPSS
1.9%
top 16.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 18
Latest updateMay 14

Description

An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages11 packages

CVEListV5mozilla/firefoxunspecified61
NVDmozilla/firefox53.060.1.0+1
CVEListV5mozilla/firefox_esrunspecified60.1+1
CVEListV5mozilla/thunderbirdunspecified60+1

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10, 18.04, Enterprise Linux 7.6, 7.5

🔴Vulnerability Details

6
GHSA
GHSA-68c7-j9qg-3xv4: An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potential2022-05-14
CVEList
CVE-2018-12362: An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potential2018-10-18
OSV
CVE-2018-12362: An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potential2018-10-18
OSV
thunderbird vulnerabilities2018-07-12
OSV
firefox regressions2018-07-10

📋Vendor Advisories

4
Ubuntu
Thunderbird vulnerabilities2018-07-12
Ubuntu
Firefox vulnerabilities2018-07-05
Red Hat
Mozilla: Integer overflow in SSSE3 scaler2018-06-26
Debian
CVE-2018-12362: firefox - An integer overflow can occur during graphics operations done by the Supplementa...2018

💬Community

1
Bugzilla
CVE-2018-12362 Mozilla: Integer overflow in SSSE3 scaler2018-06-26
CVE-2018-12362 — Integer Overflow or Wraparound | cvebase