CVE-2018-17466: Buffer Overflow
A buffer overflow and out-of-bounds read can occur in TextureStorage11 within the ANGLE graphics library, used for WebGL content. This results in a potentially exploitable crash.
Other sources
A memory corruption flaw was found in the Angle component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=880906
External References:
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
— Red Hat
Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
— Launchpad
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-17466?
CVE-2018-17466 is a vulnerability related to incorrect texture handling in Angle in Google Chrome prior to version 70.0.3538.67.
What is the severity of CVE-2018-17466?
The severity of CVE-2018-17466 is high, with a severity value of 8.8.
Which software versions are affected by CVE-2018-17466?
Mozilla Firefox versions up to 64, Google Chrome up to 70.0.3538.67, and certain versions of Redhat Enterprise Linux, Debian, and Canonical Ubuntu Linux are affected.
How can CVE-2018-17466 be exploited?
CVE-2018-17466 can be exploited through a buffer overflow and out-of-bounds read in TextureStorage11 within the ANGLE graphics library.
Where can I find more information about CVE-2018-17466?
You can find more information about CVE-2018-17466 on the Mozilla Bugzilla and Google Chromium issue pages, as well as the Mozilla Security Advisories page.