CVE-2018-18493: Buffer Overflow
A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-18493?
CVE-2018-18493 is a vulnerability in the Skia library that can result in a buffer overflow during buffer offset calculations with hardware accelerated canvas 2D actions.
Which software versions are affected by CVE-2018-18493?
Firefox ESR versions prior to 60.4 and Thunderbird versions prior to 60.4 are affected by CVE-2018-18493.
How severe is CVE-2018-18493?
CVE-2018-18493 has a severity rating of 9.8, which is considered critical.
What is the remedy for CVE-2018-18493?
To fix CVE-2018-18493, you should update to Thunderbird version 60.4 or newer, or Firefox ESR version 60.4 or newer.
Where can I find more information about CVE-2018-18493?
You can find more information about CVE-2018-18493 on the Mozilla security advisories page and the bugzilla.mozilla.org page.