First published: Wed Dec 05 2018(Updated: )
An use after free flaw was found in the PDFium component of the Chromium browser. Upstream bug(s): <a href="https://code.google.com/p/chromium/issues/detail?id=898531">https://code.google.com/p/chromium/issues/detail?id=898531</a> External References: <a href="https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html</a>
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/chromium-browser | <71.0.3578.80 | 71.0.3578.80 |
Google Chrome | <71.0.3578.80 | |
Redhat Linux Desktop | =6.0 | |
Redhat Linux Server | =6.0 | |
Redhat Linux Workstation | =6.0 | |
Debian Debian Linux | =9.0 | |
debian/chromium | 90.0.4430.212-1~deb10u1 116.0.5845.180-1~deb11u1 120.0.6099.129-1~deb11u1 119.0.6045.199-1~deb12u1 120.0.6099.129-1~deb12u1 120.0.6099.129-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18336 is a vulnerability in PDFium in Google Chrome prior to 71.0.3578.80 that allows a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2018-18336 impacts Google Chrome versions prior to 71.0.3578.80 by allowing a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2018-18336 affects Google Chrome on all operating systems prior to version 71.0.3578.80, as well as Redhat Linux Desktop, Redhat Linux Server, Redhat Linux Workstation, and Debian Linux.
CVE-2018-18336 has a severity value of 8.8, indicating a high severity.
To fix CVE-2018-18336, update Google Chrome to version 71.0.3578.80 or later. For Redhat Linux Desktop, Redhat Linux Server, and Redhat Linux Workstation, refer to the associated Redhat advisory. For Debian Linux, update the chromium package to the appropriate version.