CVE-2018-18498: Integer Overflow
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This can lead to an out-of-bounds write.
Other sources
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-18498?
CVE-2018-18498 is a potential vulnerability that can lead to an integer overflow during buffer size calculations for images, resulting in a possible out-of-bounds write.
Which software is affected by CVE-2018-18498?
Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64 are affected by CVE-2018-18498.
How severe is CVE-2018-18498?
CVE-2018-18498 has a severity rating of 9.8 (Critical).
What is the remedy for CVE-2018-18498?
Update Thunderbird to version 60.4 or later, Firefox ESR to version 60.4 or later, and Firefox to version 64 or later to fix CVE-2018-18498.
Where can I find more information about CVE-2018-18498?
More information about CVE-2018-18498 can be found at the following references: [link1], [link2], [link3].