CVE-2018-17480: Google Chromium V8 Out-of-Bounds Write Vulnerability
An out of bounds write flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=905940
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1 - Upgrade
Upgrade
redhat/chromium-browserto a version that resolves this vulnerability.Fixed in 71.0.3578.80 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 71.0.3578.80 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 116.0.5845.180-1~deb11u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1~deb11u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 119.0.6045.199-1~deb12u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1~deb12u1 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.129-1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-17481
- CVE-2018-18335
- CVE-2018-18336
- CVE-2018-18337
- CVE-2018-18338
- CVE-2018-18339
- CVE-2018-18340
- CVE-2018-18341
- CVE-2018-18342
- CVE-2018-18343
- CVE-2018-18344
- CVE-2018-18345
- CVE-2018-18346
- CVE-2018-18347
- CVE-2018-18348
- CVE-2018-18349
- CVE-2018-18350
- CVE-2018-18351
- CVE-2018-18352
- CVE-2018-18353
- CVE-2018-18354
- CVE-2018-18355
- CVE-2018-18356
- CVE-2018-18357
- CVE-2018-18358
- CVE-2018-18359
- CVE-2018-20065
- CVE-2018-20066
- CVE-2018-20067
- CVE-2018-20068
- CVE-2018-20069
- CVE-2018-20070
- CVE-2018-20071
Frequently Asked Questions
What is CVE-2018-17480?
CVE-2018-17480 is a vulnerability that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page in Google Chrome prior to version 71.0.3578.80.
Which software is affected by CVE-2018-17480?
Google Chromium V8 Engine and Google Chrome versions prior to 71.0.3578.80 are affected by CVE-2018-17480.
What is the severity of CVE-2018-17480?
CVE-2018-17480 has a severity rating of 8.8 (high).
How can I fix CVE-2018-17480?
To fix CVE-2018-17480, update Google Chrome or Google Chromium to version 71.0.3578.80 or later.
Where can I find more information about CVE-2018-17480?
You can find more information about CVE-2018-17480 on the following references: https://security-tracker.debian.org/tracker/CVE-2018-17480, http://www.securityfocus.com/bid/106084, and https://access.redhat.com/errata/RHSA-2018:3803.