CVE-2018-5160: Use After Free
Last updated 24 July 2024
Other sources
WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affects Firefox < 60.
— Launchpad
WebRTC can use a WrappedI420Buffer pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
Frequently Asked Questions
What is CVE-2018-5160?
CVE-2018-5160 is a vulnerability in WebRTC that can lead to a potentially exploitable crash.
Which software is affected by CVE-2018-5160?
This vulnerability affects Firefox versions older than 60.
How severe is CVE-2018-5160?
CVE-2018-5160 has a severity rating of high.
How can CVE-2018-5160 be exploited?
CVE-2018-5160 can be exploited by using uninitialized memory in the WebRTC encoder.
How can I fix CVE-2018-5160?
To fix CVE-2018-5160, update your Firefox browser to version 60 or later.