CVE-2018-12361: Canonical Ubuntu Linux

High severity, CVSS 8.8. EPSS: 2.8% chance of exploitation in the next 30 days.

An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Mozilla Firefox: before 61.0 (fixed in 61.0)
  • Mozilla Firefox ESR: before 60.1 (fixed in 60.1)
  • Mozilla Thunderbird: before 60.0 (fixed in 60.0)

Published 2018-10-18. Last modified 2026-06-17.