First published: Wed Dec 05 2018(Updated: )
A buffer overflow vulnerability in the Skia library can occur with Canvas 2D acceleration on macOS. This issue was addressed by disabling Canvas 2D acceleration in Firefox ESR. Note: this does not affect other versions and platforms where Canvas 2D acceleration is already disabled by default.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <71.0.3578.80 | |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Debian Debian Linux | =9.0 | |
openSUSE Leap | =15.0 | |
Mozilla Firefox ESR | <60.5.1 | 60.5.1 |
<60.5.1 | 60.5.1 | |
<60.5.1 | 60.5.1 | |
debian/chromium | 90.0.4430.212-1~deb10u1 116.0.5845.180-1~deb11u1 120.0.6099.129-1~deb11u1 119.0.6045.199-1~deb12u1 120.0.6099.129-1~deb12u1 120.0.6099.129-1 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.6.0esr-1~deb10u1 102.15.0esr-1~deb11u1 115.6.0esr-1~deb11u1 115.5.0esr-1~deb12u1 115.6.0esr-1~deb12u1 115.6.0esr-1 | |
debian/thunderbird | 1:91.12.0-1~deb10u1 1:115.6.0-1~deb10u1 1:102.13.1-1~deb11u1 1:115.6.0-1~deb11u1 1:115.5.0-1~deb12u1 1:115.6.0-1~deb12u1 1:115.6.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2018-18335.
The severity of CVE-2018-18335 is high with a score of 8.8.
Google Chrome versions prior to 71.0.3578.80, Mozilla Firefox ESR version up to 60.5.1, and Chromium versions up to 71.0.3578.80 are affected by CVE-2018-18335.
The vulnerability affects macOS, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Workstation, Debian Debian Linux, and openSUSE Leap.
To fix CVE-2018-18335, update to Google Chrome version 71.0.3578.80 or later, Mozilla Firefox ESR version 60.5.1 or later, or Chromium version 71.0.3578.80 or later.