Out-of-bounds read in Google Chrome - CVE-2018-17478
Published: November 12, 2018
Vulnerability identifier: #VU15795
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17478
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to out-of-bounds memory read in V8. A remote attacker can trick the victim into visiting a specially crafted website, trigger out-of-bounds memory access and cause the service to crash.
The weakness exists due to out-of-bounds memory read in V8. A remote attacker can trick the victim into visiting a specially crafted website, trigger out-of-bounds memory access and cause the service to crash.
Affected software
Google Chrome
Debian Linux
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Opensuse
Fedora
chromium
Debian Linux
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Opensuse
Fedora
chromium
How to mitigate CVE-2018-17478
Update to version 70.0.3538.102.
Google Chrome - update to 70.0.3538.102
chromium - addressed in versions 70.0.3538.110-1.fc28, 70.0.3538.110-1.fc29
chromium - addressed in versions 70.0.3538.110-1.fc28, 70.0.3538.110-1.fc29