Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title chromium-browser security update
Informations
Name DSA-4237 First vendor Publication 2018-06-30
Vendor Debian Last vendor Modification 2018-06-30
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 9.3 Attack Range Network
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Several vulnerabilities have been discovered in the chromium web browser.

CVE-2018-6118

Ned Williamson discovered a use-after-free issue.

CVE-2018-6120

Zhou Aiting discovered a buffer overflow issue in the pdfium library.

CVE-2018-6121

It was discovered that malicious extensions could escalate privileges.

CVE-2018-6122

A type confusion issue was discovered in the v8 javascript library.

CVE-2018-6123

Looben Yang discovered a use-after-free issue.

CVE-2018-6124

Guang Gong discovered a type confusion issue.

CVE-2018-6125

Yubico discovered that the WebUSB implementation was too permissive.

CVE-2018-6126

Ivan Fratric discovered a buffer overflow issue in the skia library.

CVE-2018-6127

Looben Yang discovered a use-after-free issue.

CVE-2018-6129

Natalie Silvanovich discovered an out-of-bounds read issue in WebRTC.

CVE-2018-6130

Natalie Silvanovich discovered an out-of-bounds read issue in WebRTC.

CVE-2018-6131

Natalie Silvanovich discovered an error in WebAssembly.

CVE-2018-6132

Ronald E. Crane discovered an uninitialized memory issue.

CVE-2018-6133

Khalil Zhani discovered a URL spoofing issue.

CVE-2018-6134

Jun Kokatsu discovered a way to bypass the Referrer Policy.

CVE-2018-6135

Jasper Rebane discovered a user interface spoofing issue.

CVE-2018-6136

Peter Wong discovered an out-of-bounds read issue in the v8 javascript library.

CVE-2018-6137

Michael Smith discovered an information leak.

CVE-2018-6138

François Lajeunesse-Robert discovered that the extensions policy was too permissive.

CVE-2018-6139

Rob Wu discovered a way to bypass restrictions in the debugger extension.

CVE-2018-6140

Rob Wu discovered a way to bypass restrictions in the debugger extension.

CVE-2018-6141

Yangkang discovered a buffer overflow issue in the skia library.

CVE-2018-6142

Choongwoo Han discovered an out-of-bounds read in the v8 javascript library.

CVE-2018-6143

Guang Gong discovered an out-of-bounds read in the v8 javascript library.

CVE-2018-6144

pdknsk discovered an out-of-bounds read in the pdfium library.

CVE-2018-6145

Masato Kinugawa discovered an error in the MathML implementation.

CVE-2018-6147

Michail Pishchagin discovered an error in password entry fields.

CVE-2018-6148

Michał Bentkowski discovered that the Content Security Policy header was handled incorrectly.

CVE-2018-6149

Yu Zhou and Jundong Xie discovered an out-of-bounds write issue in the v8 javascript library.

For the stable distribution (stretch), these problems have been fixed in version 67.0.3396.87-1~deb9u1.

We recommend that you upgrade your chromium-browser packages.

For the detailed security status of chromium-browser please refer to its security tracker page at: https://security-tracker.debian.org/tracker/chromium-browser

Original Source

Url : http://www.debian.org/security/2018/dsa-4237

CWE : Common Weakness Enumeration

% Id Name
22 % CWE-787 Out-of-bounds Write (CWE/SANS Top 25)
22 % CWE-125 Out-of-bounds Read
15 % CWE-20 Improper Input Validation
11 % CWE-416 Use After Free
11 % CWE-200 Information Exposure
4 % CWE-704 Incorrect Type Conversion or Cast
4 % CWE-190 Integer Overflow or Wraparound (CWE/SANS Top 25)
4 % CWE-93 Failure to Sanitize CRLF Sequences ('CRLF Injection')
4 % CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25)
4 % CWE-19 Data Handling

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 4058
Os 2
Os 4
Os 1
Os 1
Os 1

Nessus® Vulnerability Scanner

Date Description
2019-01-03 Name : The remote Fedora host is missing a security update.
File : fedora_2018-94e1bc8c23.nasl - Type : ACT_GATHER_INFO
2019-01-03 Name : The remote Fedora host is missing a security update.
File : fedora_2018-7c80aaef26.nasl - Type : ACT_GATHER_INFO
2019-01-03 Name : The remote Fedora host is missing a security update.
File : fedora_2018-499f2dbc96.nasl - Type : ACT_GATHER_INFO
2018-10-03 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201810-01.nasl - Type : ACT_GATHER_INFO
2018-09-24 Name : The remote Fedora host is missing a security update.
File : fedora_2018-4a16e37c81.nasl - Type : ACT_GATHER_INFO
2018-07-16 Name : The remote CentOS host is missing a security update.
File : centos_RHSA-2018-2112.nasl - Type : ACT_GATHER_INFO
2018-07-12 Name : The remote CentOS host is missing a security update.
File : centos_RHSA-2018-2113.nasl - Type : ACT_GATHER_INFO
2018-07-02 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-4237.nasl - Type : ACT_GATHER_INFO
2018-06-21 Name : The remote Fedora host is missing a security update.
File : fedora_2018-09b59b0227.nasl - Type : ACT_GATHER_INFO
2018-06-20 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201806-06.nasl - Type : ACT_GATHER_INFO
2018-06-11 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_4cb49a236c8911e88b33e8e0b747a45a.nasl - Type : ACT_GATHER_INFO
2018-06-11 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-4220.nasl - Type : ACT_GATHER_INFO
2018-06-06 Name : The remote Fedora host is missing a security update.
File : fedora_2018-812b5d5a71.nasl - Type : ACT_GATHER_INFO
2018-05-31 Name : A web browser installed on the remote host is affected by multiple vulnerabil...
File : macosx_google_chrome_67_0_3396_62.nasl - Type : ACT_GATHER_INFO
2018-05-31 Name : A web browser installed on the remote Windows host is affected by multiple vu...
File : google_chrome_67_0_3396_62.nasl - Type : ACT_GATHER_INFO
2018-05-31 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_427b0f58644c11e89e1be8e0b747a45a.nasl - Type : ACT_GATHER_INFO
2018-05-21 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201805-06.nasl - Type : ACT_GATHER_INFO
2018-05-17 Name : A web browser installed on the remote host is affected by multiple vulnerabil...
File : macosx_google_chrome_66_0_3359_170.nasl - Type : ACT_GATHER_INFO
2018-05-17 Name : A web browser installed on the remote Windows host is affected by multiple vu...
File : google_chrome_66_0_3359_170.nasl - Type : ACT_GATHER_INFO
2018-05-14 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_e457978b548411e89b8554ee754af08e.nasl - Type : ACT_GATHER_INFO
2018-05-03 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201805-03.nasl - Type : ACT_GATHER_INFO
2018-05-01 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_006bee4e4c4911e89c3254ee754af08e.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
Date Informations
2019-10-03 09:24:27
  • Multiple Updates
2019-01-16 17:21:18
  • Multiple Updates
2019-01-15 00:21:09
  • Multiple Updates
2019-01-10 17:21:20
  • Multiple Updates
2018-07-01 05:17:22
  • First insertion