An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 61.0 |
| mozilla / thunderbird | - | 60.0 |
| mozilla / firefox_esr | - | 60.1 |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 9.0 | 9.0.x |
| canonical / ubuntu_linux | 16.04 | 16.04.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| canonical / ubuntu_linux | 17.10 | 17.10.x |
| canonical / ubuntu_linux | 18.04 | 18.04.x |