CVE-2018-18356

Source
Severity High
Remote Yes
Type Arbitrary code execution
Description
A use-after-free has been found in the Skia component of chromium before 71.0.3578.80 and firefox before 65.0.1 and thunderbird before 60.5.1.
Group Package Affected Fixed Severity Status Ticket
AVG-908 thunderbird 60.5.0-1 60.5.1-1 Critical Fixed
AVG-896 firefox 65.0-2 65.0.1-1 High Fixed
AVG-824 chromium 70.0.3538.110-1 71.0.3578.80-1 Critical Fixed
Date Advisory Group Package Severity Description
20 Feb 2019 ASA-201902-23 AVG-908 thunderbird Critical multiple issues
13 Feb 2019 ASA-201902-16 AVG-896 firefox High multiple issues
08 Dec 2018 ASA-201812-2 AVG-824 chromium Critical multiple issues
References
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
https://bugs.chromium.org/p/chromium/issues/detail?id=883666
https://www.mozilla.org/en-US/security/advisories/mfsa2019-04/#CVE-2018-18356
https://www.mozilla.org/en-US/security/advisories/mfsa2019-06/#CVE-2018-18356
https://bugzilla.mozilla.org/show_bug.cgi?id=1525817