CVE-2018-18336: Use After Free
An use after free flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=898531
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Incorrect object lifecycle in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-18336?
CVE-2018-18336 is a vulnerability in PDFium in Google Chrome prior to 71.0.3578.80 that allows a remote attacker to potentially exploit heap corruption via a crafted PDF file.
How does CVE-2018-18336 impact Google Chrome?
CVE-2018-18336 impacts Google Chrome versions prior to 71.0.3578.80 by allowing a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Which operating systems are affected by CVE-2018-18336?
CVE-2018-18336 affects Google Chrome on all operating systems prior to version 71.0.3578.80, as well as Redhat Linux Desktop, Redhat Linux Server, Redhat Linux Workstation, and Debian Linux.
What is the severity of CVE-2018-18336?
CVE-2018-18336 has a severity value of 8.8, indicating a high severity.
How can I fix CVE-2018-18336?
To fix CVE-2018-18336, update Google Chrome to version 71.0.3578.80 or later. For Redhat Linux Desktop, Redhat Linux Server, and Redhat Linux Workstation, refer to the associated Redhat advisory. For Debian Linux, update the chromium package to the appropriate version.