Vulnerability CVE-2018-12359: Information

Description

A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be written outside of the currently computed boundaries. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

Severity: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: Oct. 18, 2018
Modified: Dec. 6, 2018
Error type identifier: CWE-119

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://www.mozilla.org/security/advisories/mfsa2018-19/
  • Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-18/
  • Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-17/
  • Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-16/
  • Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-15/
  • Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1459162
  • Issue Tracking
  • Vendor Advisory
  • Permissions Required
DSA-4244
  • Third Party Advisory
DSA-4235
  • Third Party Advisory
USN-3714-1
  • Third Party Advisory
USN-3705-1
  • Third Party Advisory
[debian-lts-announce] 20180714 [SECURITY] [DLA 1425-1] thunderbird security update
  • Mailing List
  • Third Party Advisory
[debian-lts-announce] 20180629 [SECURITY] [DLA 1406-1] firefox-esr security update
  • Mailing List
  • Third Party Advisory
RHSA-2018:2252
  • Third Party Advisory
RHSA-2018:2251
  • Third Party Advisory
RHSA-2018:2113
  • Third Party Advisory
RHSA-2018:2112
  • Third Party Advisory
1041193
  • VDB Entry
  • Third Party Advisory
104555
  • Third Party Advisory
  • VDB Entry
GLSA-201810-01
  • Third Party Advisory
GLSA-201811-13
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

      Configuration 4

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
      End excliding
      61.0

      cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
      End excliding
      52.9

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
      End excliding
      52.9

      cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
      Start including
      53.0
      End excliding
      60.1

      cpe:2.3:a:mozilla:thunderbird:52.9.1:*:*:*:*:*:*:*