CVE-2018-10193: High severity logmein lastpass vulnerability
Published Apr 18, 2018
·Updated
LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document because the resource consumption of onloadwff.js grows with the number of INPUT elements.
Affected Software
1 affected component
LogMeIn Lastpass Chrome<=4.15.0
Event History
Apr 18, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10193?
CVE-2018-10193 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2018-10193?
To mitigate CVE-2018-10193, update LogMeIn LastPass to version 4.15.1 or later.
3
Who is affected by CVE-2018-10193?
Individuals using LogMeIn LastPass versions up to 4.15.0 on Chrome may be affected by CVE-2018-10193.
4
What type of attack is CVE-2018-10193?
CVE-2018-10193 allows remote attackers to perform a denial of service attack resulting in browser hangs.
5
What is the cause of the vulnerability CVE-2018-10193?
CVE-2018-10193 is caused by excessive resource consumption in the onloadwff.js file related to the number of INPUT elements in an HTML document.