First published: Wed Dec 05 2018(Updated: )
An use after free flaw was found in the Skia component of the Chromium browser. Upstream bug(s): <a href="https://code.google.com/p/chromium/issues/detail?id=882423">https://code.google.com/p/chromium/issues/detail?id=882423</a> External References: <a href="https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html</a>
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <71.0.3578.80 | |
Redhat Linux Desktop | =6.0 | |
Redhat Linux Server | =6.0 | |
Redhat Linux Workstation | =6.0 | |
Debian Debian Linux | =9.0 | |
debian/chromium | 90.0.4430.212-1~deb10u1 116.0.5845.180-1~deb11u1 120.0.6099.129-1~deb11u1 119.0.6045.199-1~deb12u1 120.0.6099.129-1~deb12u1 120.0.6099.129-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18343 refers to an incorrect handling of paths leading to a use after free vulnerability in Skia in Google Chrome prior to version 71.0.3578.80.
A remote attacker can potentially exploit the vulnerability by crafting a malicious HTML page that triggers heap corruption.
Google Chrome versions prior to 71.0.3578.80, Redhat Linux Desktop 6.0, Redhat Linux Server 6.0, Redhat Linux Workstation 6.0, and Debian Debian Linux 9.0 are affected.
CVE-2018-18343 has a high severity rating of 8.8.
To fix CVE-2018-18343, update Google Chrome to version 71.0.3578.80 or later. For other affected software, follow the remediation steps provided by the respective vendors.