CVE-2018-12371Integer Overflow or Wraparound in Mozilla Firefox

Severity
8.8HIGHNVD
OSV4.3
EPSS
0.5%
top 34.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 9
Latest updateMay 24

Description

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages7 packages

CVEListV5mozilla/firefoxunspecified61
NVDmozilla/firefox< 60.1.0+1
CVEListV5mozilla/firefox_esrunspecified60.1
Ubuntumozilla/firefox< 61.0.1+build1-0ubuntu0.14.04.1+5
CVEListV5mozilla/thunderbirdunspecified60

Patches

🔴Vulnerability Details

5
GHSA
GHSA-jvm4-fpvm-vr72: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM2022-05-24
CVEList
CVE-2018-12371: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM2020-07-09
OSV
CVE-2018-12371: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM2020-07-09
OSV
firefox regressions2018-07-10
OSV
firefox vulnerabilities2018-07-05

📋Vendor Advisories

4
Ubuntu
Firefox regressions2018-07-10
Ubuntu
Firefox vulnerabilities2018-07-05
Red Hat
Mozilla: Integer overflow in Skia library during edge builder allocation2018-06-26
Debian
CVE-2018-12371: firefox - An integer overflow vulnerability in the Skia library when allocating memory for...2018

💬Community

2
Bugzilla
CVE-2018-12371 Mozilla: Integer overflow in Skia library during edge builder allocation2018-06-26
Bugzilla
Heap overflow write in SkEdgeBuilder::buildPoly2018-05-31
CVE-2018-12371 — Integer Overflow or Wraparound | cvebase