First published: Thu Aug 11 2016(Updated: )
Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local files via a crafted HTML page.
Credit: Abdulrahman Alqabandi @qab cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/chromium-browser | <66.0.3359.117 | 66.0.3359.117 |
Redhat Linux Desktop | =6.0 | |
Redhat Linux Server | =6.0 | |
Redhat Linux Workstation | =6.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Google Chrome | <66.0.3359.117 | |
debian/chromium-browser | ||
Google Chrome | <66.0.3359.117 | 66.0.3359.117 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2018-6095 is medium, with a severity value of 6.5.
A remote attacker can exploit CVE-2018-6095 by crafting a malicious HTML page that allows them to read local files.
The affected software for CVE-2018-6095 includes Google Chrome prior to version 66.0.3359.117, Chromium Browser (package) on Debian and Redhat Linux Desktop, Server, and Workstation (version 6.0), and Debian Linux (versions 8.0 and 9.0).
To fix CVE-2018-6095 in Google Chrome, you need to update to version 66.0.3359.117 or later.
You can find more information about CVE-2018-6095 on the Debian Security Tracker, Google Chromium issues page, and the Google Chrome Stable Channel Updates blog post.