Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-5159. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates an integer overflow vulnerability in Skia's SkTDArray, leading to an out-of-bounds write when rendering dashed paths. The PoC triggers a crash via memory corruption in both a standalone Skia application and Mozilla Firefox.
Description
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
Exploits (1)
This exploit demonstrates an integer overflow vulnerability in Skia's SkTDArray, leading to an out-of-bounds write when rendering dashed paths. The PoC triggers a crash via memory corruption in both a standalone Skia application and Mozilla Firefox.
References (19)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H