Memory corruption - CVE-2018-12293

 

Memory corruption - CVE-2018-12293

Published: June 25, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU13509
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12293
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists in the getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp due to integer overflow when handling malicious input. A remote attacker can trick the victim into visiting a specially crafted website, trigger heap-based buffer overflow and execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Gentoo Linux
Ubuntu

How to mitigate CVE-2018-12293

Update to version 2.20.1, 2.20.3.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins