First published: Fri Apr 20 2018(Updated: )
An integer overflow flaw was found in the SwiftShader component of the Chromium browser. Upstream bug(s): <a href="https://code.google.com/p/chromium/issues/detail?id=835299">https://code.google.com/p/chromium/issues/detail?id=835299</a> External References: <a href="https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html</a>
Credit: Mark Brand Google Project Zero cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/chromium-browser | <68.0.3440.75 | 68.0.3440.75 |
Google Chrome | <68.0.3440.75 | |
Debian Debian Linux | =9.0 | |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Workstation | =6.0 | |
debian/chromium-browser | ||
Google Chrome | <68.0.3440.75 | 68.0.3440.75 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-6174 is an integer overflow vulnerability in SwiftShader in Google Chrome prior to version 68.0.3440.75.
CVE-2018-6174 potentially allows a remote attacker to execute arbitrary code via a crafted HTML page in Google Chrome prior to version 68.0.3440.75.
Versions of Google Chrome prior to 68.0.3440.75, Debian Linux 9.0, and Redhat Enterprise Linux Desktop, Server, and Workstation 6.0 are affected by CVE-2018-6174.
CVE-2018-6174 has a severity rating of 8.8 (high).
To fix CVE-2018-6174, update Google Chrome to version 68.0.3440.75 or newer.