CVE-2018-12393: Integer Overflow
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write.
Note: 64-bit builds are not vulnerable to this issue.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12393
Other sources
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. Note: 64-bit builds are not vulnerable to this issue.. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
— Launchpad
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. Note: 64-bit builds are not vulnerable to this issue.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2018-12393?
CVE-2018-12393 has a severity rating classified as moderate, indicating potential impact but requiring specific conditions to exploit.
How do I fix CVE-2018-12393?
To fix CVE-2018-12393, upgrade to the latest versions of affected software such as Mozilla Firefox ESR beyond 60.3 or Mozilla Thunderbird beyond 60.3.
Which versions are affected by CVE-2018-12393?
CVE-2018-12393 affects 32-bit builds of Mozilla Firefox versions up to 63 and Mozilla Thunderbird versions up to 60.3.
Can CVE-2018-12393 be exploited remotely?
Yes, CVE-2018-12393 can potentially be exploited remotely through malicious scripts that trigger the integer overflow.
What platforms are impacted by CVE-2018-12393?
CVE-2018-12393 impacts various platforms including Windows and Linux distributions using affected versions of Mozilla Firefox and Thunderbird.