Race condition in Google Chrome - CVE-2018-6033
Published: January 25, 2018 / Updated: June 6, 2021
Vulnerability details
The vulnerability exists due to race condition when opening downloaded files. A remote attacker can trick the victim into opening a specially crafted file, trigger race condition and execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Debian Linux
Gentoo Linux
Red Hat Enterprise Linux for x86_64
SUSE Linux
Fedora
Opensuse
qt5-qtwebengine
How to mitigate CVE-2018-6033
qt5-qtwebengine - addressed in versions 5.10.1-1.fc26, 5.10.1-1.fc27, 5.10.1-4.fc26, 5.10.1-4.fc27, 5.10.1-4.fc28
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Chrome
- openSUSE update for chromium
- Debian update for chromium-browser
- SUSE Linux update for chromium
- Red Hat update for Google Chrome
- Gentoo update for Chromium, Google Chrome
- Fedora 27 update for qt5-qtwebengine
- Fedora 26 update for qt5-qtwebengine
- Fedora 26 update for qt5-qtwebengine
- Fedora 28 update for qt5-qtwebengine
- Fedora 27 update for qt5-qtwebengine