CVE-2018-6079: Infoleak
An information disclosure via texture data flaw was found in the WebGL component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=788448
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Other sources
Inappropriate sharing of TEXTURE2DARRAY/TEXTURE3D data between tabs in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6079?
CVE-2018-6079 is classified as a medium severity vulnerability.
How do I fix CVE-2018-6079?
To fix CVE-2018-6079, update your Chromium browser to version 65.0.3325.146 or later.
What types of systems are affected by CVE-2018-6079?
CVE-2018-6079 affects multiple versions of the Chromium browser and Debian, Red Hat Enterprise Linux Desktop, Server, and Workstation.
What does CVE-2018-6079 disclose?
CVE-2018-6079 represents an information disclosure vulnerability via texture data in the WebGL component.
Is there a workaround for CVE-2018-6079?
There are no known workarounds for CVE-2018-6079, so upgrading the software is recommended.