CVE-2018-5095: Integer Overflow
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5095
- CVE-2018-5096
- CVE-2018-5097
- CVE-2018-5098
- CVE-2018-5099
- CVE-2018-5102
- CVE-2018-5103
- CVE-2018-5104
- CVE-2018-5117
- CVE-2018-5089
- CVE-2018-5091
- CVE-2018-5092
- CVE-2018-5093
- CVE-2018-5094
- CVE-2018-5100
- CVE-2018-5101
- CVE-2018-5105
- CVE-2018-5106
- CVE-2018-5107
- CVE-2018-5108
- CVE-2018-5109
- CVE-2018-5110
- CVE-2018-5111
- CVE-2018-5112
- CVE-2018-5113
- CVE-2018-5114
- CVE-2018-5115
- CVE-2018-5116
- CVE-2018-5118
- CVE-2018-5119
- CVE-2018-5121
- CVE-2018-5122
- CVE-2018-5090
Frequently Asked Questions
What is CVE-2018-5095?
CVE-2018-5095 is an integer overflow vulnerability in the Skia library that can result in a potentially exploitable crash.
Which software versions are affected by CVE-2018-5095?
The vulnerability affects Thunderbird versions <52.6 and Firefox ESR versions <52.6.
How severe is CVE-2018-5095?
CVE-2018-5095 has a severity score of 9.8, which is considered critical.
What is the remedy for CVE-2018-5095 on Ubuntu?
For Ubuntu, the remedy for CVE-2018-5095 is to upgrade Firefox to version 58.0 or higher or Thunderbird to version 52.6.0 or higher.
Where can I find more information about CVE-2018-5095?
You can find more information about CVE-2018-5095 on the Mozilla Bugzilla website, the Mozilla security advisories page, and the SecurityFocus website.