CVE-2018-18335: Buffer Overflow
A buffer overflow vulnerability in the Skia library can occur with Canvas 2D acceleration on macOS. This issue was addressed by disabling Canvas 2D acceleration in Firefox ESR. Note: this does not affect other versions and platforms where Canvas 2D acceleration is already disabled by default.
Other sources
A heap buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=895362
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
— Red Hat
Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected Software
Remediation
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-18335.
What is the severity of CVE-2018-18335?
The severity of CVE-2018-18335 is high with a score of 8.8.
Which software versions are affected by CVE-2018-18335?
Google Chrome versions prior to 71.0.3578.80, Mozilla Firefox ESR version up to 60.5.1, and Chromium versions up to 71.0.3578.80 are affected by CVE-2018-18335.
What platforms are affected by CVE-2018-18335?
The vulnerability affects macOS, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Workstation, Debian Debian Linux, and openSUSE Leap.
How can I fix CVE-2018-18335?
To fix CVE-2018-18335, update to Google Chrome version 71.0.3578.80 or later, Mozilla Firefox ESR version 60.5.1 or later, or Chromium version 71.0.3578.80 or later.