CVE-2018-10799: Input Validation
Published May 7, 2018
·Updated
A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux). This vulnerability is caused by the mishandling of a long URL formed by window.location+='?\u202a\uFEFF\u202b'; concatenation in a SCRIPT element.
Affected Software
1 affected component
Brave Brave Linux Kernel<0.14.0
Event History
May 7, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-10799?
CVE-2018-10799 is a hang issue discovered in Brave before 0.14.0, specifically on Linux systems.
2
How does CVE-2018-10799 affect Brave?
CVE-2018-10799 allows an attacker to cause a hang issue in Brave before version 0.14.0 on Linux systems.
3
What is the severity level of CVE-2018-10799?
The severity level of CVE-2018-10799 is medium with a CVSS score of 6.5.
4
How can I fix CVE-2018-10799?
To fix CVE-2018-10799, you should update Brave to version 0.14.0 or newer.