CVE-2018-18340: Use After Free
An use after free flaw was found in the MediaRecorder component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=896736
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Other sources
Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-18340?
CVE-2018-18340 is a vulnerability in Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Which software versions are affected by CVE-2018-18340?
Google Chrome versions prior to 71.0.3578.80 are affected by CVE-2018-18340. Redhat Linux Desktop, Server, and Workstation versions 6.0 are also affected. Debian Linux version 9.0 and the chromium-browser and chromium packages in Debian are also affected.
What is the severity of CVE-2018-18340?
CVE-2018-18340 has a severity rating of 8.8 (High).
Where can I find more information about CVE-2018-18340?
You can find more information about CVE-2018-18340 at the following references: [1] https://security-tracker.debian.org/tracker/CVE-2018-18340, [2] http://www.securityfocus.com/bid/106084, [3] https://access.redhat.com/errata/RHSA-2018:3803
How can I fix CVE-2018-18340?
To fix CVE-2018-18340, update Google Chrome to version 71.0.3578.80 or later. For Redhat Linux, apply the necessary patches as indicated in the Redhat Security Advisory RHSA-2018:3803. For Debian Linux, update the chromium-browser and chromium packages to the recommended versions.