Your submission was sent successfully! Close

CVE-2018-5160

Published: 11 May 2018

WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affects Firefox < 60.

Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
artful
Released (60.0+build2-0ubuntu0.17.10.1)
bionic
Released (60.0+build2-0ubuntu1)
precise Does not exist

trusty Does not exist
(trusty was released [60.0+build2-0ubuntu0.14.04.1])
upstream
Released (60.0)
xenial
Released (60.0+build2-0ubuntu0.16.04.1)