CVE-2018-12361 - log back

CVE-2018-12361 created at 25 Sep 2019 19:31:40
Severity
+ Critical
Remote
+ Remote
Type
+ Arbitrary code execution
Description
+ An integer overflow can occur in Firefox before 61.0 and Thunderbird before 60.0 in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which results in a potentially exploitable crash.
References
+ https://www.mozilla.org/en-US/security/advisories/mfsa2018-15/#CVE-2018-12361
+ https://bugzilla.mozilla.org/show_bug.cgi?id=1463244
Notes