First published: Wed Oct 17 2018(Updated: )
A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/chromium-browser | ||
redhat/chromium-browser | <70.0.3538.67 | 70.0.3538.67 |
Google Chrome (Trace Event) | <70.0.3538.67 | |
Debian | =9.0 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Workstation | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17470 has been assigned a high severity rating due to its potential for sandbox escape and exploitation.
To fix CVE-2018-17470, update your Google Chrome or Chromium browser to version 70.0.3538.67 or later.
CVE-2018-17470 affects versions of Chrome prior to 70.0.3538.67.
Yes, CVE-2018-17470 can potentially allow a remote attacker to execute code via a crafted HTML page.
CVE-2018-17470 impacts multiple platforms including Debian and Red Hat enterprise Linux systems running affected versions of Chrome or Chromium.