First published: Wed Dec 05 2018(Updated: )
An use after frees flaw was found in the PDFium component of the Chromium browser. Upstream bug(s): <a href="https://code.google.com/p/chromium/issues/detail?id=901654">https://code.google.com/p/chromium/issues/detail?id=901654</a> External References: <a href="https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html</a>
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/chromium | 90.0.4430.212-1~deb10u1 116.0.5845.180-1~deb11u1 120.0.6099.129-1~deb11u1 119.0.6045.199-1~deb12u1 120.0.6099.129-1~deb12u1 120.0.6099.129-1 | |
Google Chrome | <71.0.3578.98 | |
Redhat Linux Desktop | =6.0 | |
Redhat Linux Server | =6.0 | |
Redhat Linux Workstation | =6.0 | |
Debian Debian Linux | =9.0 | |
redhat/chromium-browser | <71.0.3578.80 | 71.0.3578.80 |
Google Chrome | <71.0.3578.98 | 71.0.3578.98 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17481 is a vulnerability in PDFium in Google Chrome prior to version 71.0.3578.98 that allows a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2018-17481 has a severity score of 8.8 and is considered high.
Google Chrome prior to version 71.0.3578.98, Redhat Linux Desktop 6.0, Redhat Linux Server 6.0, Redhat Linux Workstation 6.0, and Debian Debian Linux 9.0 are affected by CVE-2018-17481.
An attacker can potentially exploit CVE-2018-17481 by using a crafted PDF file to trigger heap corruption.
To fix CVE-2018-17481, update Google Chrome to version 71.0.3578.98 or later, or apply the appropriate security patches from Redhat or Debian.