Out-of-bounds read in Google Chrome - CVE-2018-17478

 

Out-of-bounds read in Google Chrome - CVE-2018-17478

Published: November 12, 2018


Vulnerability identifier: #VU15795
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17478
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to out-of-bounds memory read in V8. A remote attacker can trick the victim into visiting a specially crafted website, trigger out-of-bounds memory access and cause the service to crash.

Affected software

Google Chrome
Debian Linux
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Opensuse
Fedora
chromium

How to mitigate CVE-2018-17478

Update to version 70.0.3538.102.

Google Chrome - update to 70.0.3538.102
chromium - addressed in versions 70.0.3538.110-1.fc28, 70.0.3538.110-1.fc29

External References

Related Security Bulletins