CVE-2018-6067: Buffer Overflow
A buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=779428
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Other sources
Incorrect IPC serialization in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6067?
CVE-2018-6067 has been rated as high severity due to the potential for arbitrary code execution resulting from a buffer overflow.
How do I fix CVE-2018-6067?
To fix CVE-2018-6067, update the Chromium browser to version 65.0.3325.146 or later.
What impact does CVE-2018-6067 have on affected software?
CVE-2018-6067 can allow an attacker to execute arbitrary code within the context of the user running the Chromium browser.
Which versions of Chromium are affected by CVE-2018-6067?
Chromium versions prior to 65.0.3325.146 are affected by CVE-2018-6067.
Is CVE-2018-6067 specific to any operating system?
CVE-2018-6067 affects various operating systems running the vulnerable versions of the Chromium browser.