CVE-2018-12362: Integer Overflow
An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploitable crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 60 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 52.9 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 61 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 60.1 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 52.9 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 147.0.4-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 140.7.0esr-1~deb11u1Fixed in 128.14.0esr-1~deb12u1Fixed in 140.7.0esr-1~deb12u1Fixed in 140.4.0esr-1~deb13u1Fixed in 140.7.0esr-1~deb13u1Fixed in 140.7.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.7.1esr-1~deb11u1Fixed in 1:140.6.0esr-1~deb12u1Fixed in 1:140.7.1esr-1~deb12u1Fixed in 1:140.6.0esr-1~deb13u1Fixed in 1:140.7.1esr-1~deb13u1Fixed in 1:140.7.1esr-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 60 - Upgrade
Upgrade
Mozilla Thunderbird / Firefoxto a version that resolves this vulnerability.Fixed in 60 - Upgrade
Upgrade
Mozilla Thunderbird / Firefoxto a version that resolves this vulnerability.Fixed in 52.9 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 60.1 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 61
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-12362?
CVE-2018-12362 has been classified as a potentially exploitable vulnerability that may lead to a crash during graphics operations.
How do I fix CVE-2018-12362?
To fix CVE-2018-12362, upgrade to the latest versions of affected products including Mozilla Firefox ESR after version 52.9 and Thunderbird after version 60.
Which software versions are affected by CVE-2018-12362?
CVE-2018-12362 affects Mozilla Firefox versions up to 61, Thunderbird versions up to 60, and specific versions of Red Hat and Debian distributions.
What are the potential impacts of exploiting CVE-2018-12362?
Exploiting CVE-2018-12362 could lead to application crashes, which may be leveraged for further attacks or denial of service.
Is CVE-2018-12362 specific to certain operating systems?
Yes, CVE-2018-12362 affects multiple operating systems including various versions of Red Hat Enterprise Linux and Debian.