#VU13509 Memory corruption - CVE-2018-12293 

 

#VU13509 Memory corruption - CVE-2018-12293

Published: June 25, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU13509
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber
CVE-ID: CVE-2018-12293
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
Software vendor:

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists in the getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp due to integer overflow when handling malicious input. A remote attacker can trick the victim into visiting a specially crafted website, trigger heap-based buffer overflow and execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Update to version 2.20.1, 2.20.3.

External links