CVE-2018-5159: Integer Overflow
Published May 9, 2018
·Updated
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content.
Affected Software
28 affected componentsFixes available
Mozilla Thunderbird<52.8
52.8
Mozilla Firefox<60
60
Mozilla Firefox ESR<52.8
52.8
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
Mozilla Firefox<60.0
Mozilla Firefox ESR<52.8.0
Mozilla Thunderbird<52.8.0
Mozilla Thunderbird ESR<52.8.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
Mozilla Firefox<52.8.0
debian/firefox
148.0-1
debian/firefox-esr
115.14.0esr-1~deb11u1140.7.0esr-1~deb11u1128.14.0esr-1~deb12u1140.8.0esr-1~deb12u1140.4.0esr-1~deb13u1140.8.0esr-1~deb13u1140.7.0esr-1140.8.0esr-1
debian/thunderbird
1:115.12.0-1~deb11u11:140.8.0esr-1~deb11u11:140.6.0esr-1~deb12u11:140.8.0esr-1~deb12u11:140.6.0esr-1~deb13u11:140.8.0esr-1~deb13u11:140.7.1esr-11:140.8.0esr-1
Event History
May 9, 2018
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Red Hat·07:13 AM
DescriptionSeverityAffected Software
Jun 11, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:06 PM
Description
Feb 21, 2026
Data Sourced
via Ubuntu·12:50 AM
RemedyDescriptionSeverityAffected Software
Mar 1, 2026
Data Sourced
via Debian·12:57 AM
DescriptionAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5183
- CVE-2018-5184
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5159
- CVE-2018-5161
- CVE-2018-5162
- CVE-2018-5170
- CVE-2018-5168
- CVE-2018-5174
- CVE-2018-5178
- CVE-2018-5185
- CVE-2018-5150
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2018-5159.
2
What is the severity of CVE-2018-5159?
The severity of CVE-2018-5159 is critical (9.8).
3
How does CVE-2018-5159 affect Thunderbird?
CVE-2018-5159 affects Thunderbird versions below 52.8.
4
How does CVE-2018-5159 affect Firefox ESR?
CVE-2018-5159 affects Firefox ESR versions below 52.8.
5
Are there any known remedies or patches for CVE-2018-5159?
Yes, there are known remedies and patches for CVE-2018-5159. Please refer to the provided references for more information.