CVE-2018-12361

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-12361
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-12361.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-12361
Downstream
Related
Published
2018-10-18T13:29:01Z
Modified
2025-08-09T20:01:25Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.

References

Affected packages