Action not permitted
Modal body text goes here.
CVE-2018-4117
Vulnerability from cvelistv5
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-05T05:04:29.828Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "1040604", "tags": [ "vdb-entry", "x_refsource_SECTRACK", "x_transferred" ], "url": "http://www.securitytracker.com/id/1040604" }, { "name": "GLSA-201808-04", "tags": [ "vendor-advisory", "x_refsource_GENTOO", "x_transferred" ], "url": "https://security.gentoo.org/glsa/201808-04" }, { "name": "RHSA-2018:2282", "tags": [ "vendor-advisory", "x_refsource_REDHAT", "x_transferred" ], "url": "https://access.redhat.com/errata/RHSA-2018:2282" }, { "name": "GLSA-201808-01", "tags": [ "vendor-advisory", "x_refsource_GENTOO", "x_transferred" ], "url": "https://security.gentoo.org/glsa/201808-01" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://support.apple.com/HT208696" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://support.apple.com/HT208693" }, { "name": "DSA-4256", "tags": [ "vendor-advisory", "x_refsource_DEBIAN", "x_transferred" ], "url": "https://www.debian.org/security/2018/dsa-4256" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://support.apple.com/HT208694" }, { "name": "104887", "tags": [ "vdb-entry", "x_refsource_BID", "x_transferred" ], "url": "http://www.securityfocus.com/bid/104887" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://support.apple.com/HT208697" }, { "name": "USN-3635-1", "tags": [ "vendor-advisory", "x_refsource_UBUNTU", "x_transferred" ], "url": "https://usn.ubuntu.com/3635-1/" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://support.apple.com/HT208695" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "datePublic": "2018-03-29T00:00:00", "descriptions": [ { "lang": "en", "value": "An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the \"WebKit\" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2018-10-21T09:57:02", "orgId": "286789f9-fbc2-4510-9f9a-43facdede74c", "shortName": "apple" }, "references": [ { "name": "1040604", "tags": [ "vdb-entry", "x_refsource_SECTRACK" ], "url": "http://www.securitytracker.com/id/1040604" }, { "name": "GLSA-201808-04", "tags": [ "vendor-advisory", "x_refsource_GENTOO" ], "url": "https://security.gentoo.org/glsa/201808-04" }, { "name": "RHSA-2018:2282", "tags": [ "vendor-advisory", "x_refsource_REDHAT" ], "url": "https://access.redhat.com/errata/RHSA-2018:2282" }, { "name": "GLSA-201808-01", "tags": [ "vendor-advisory", "x_refsource_GENTOO" ], "url": "https://security.gentoo.org/glsa/201808-01" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://support.apple.com/HT208696" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://support.apple.com/HT208693" }, { "name": "DSA-4256", "tags": [ "vendor-advisory", "x_refsource_DEBIAN" ], "url": "https://www.debian.org/security/2018/dsa-4256" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://support.apple.com/HT208694" }, { "name": "104887", "tags": [ "vdb-entry", "x_refsource_BID" ], "url": "http://www.securityfocus.com/bid/104887" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://support.apple.com/HT208697" }, { "name": "USN-3635-1", "tags": [ "vendor-advisory", "x_refsource_UBUNTU" ], "url": "https://usn.ubuntu.com/3635-1/" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://support.apple.com/HT208695" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "product-security@apple.com", "ID": "CVE-2018-4117", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the \"WebKit\" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "1040604", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id/1040604" }, { "name": "GLSA-201808-04", "refsource": "GENTOO", "url": "https://security.gentoo.org/glsa/201808-04" }, { "name": "RHSA-2018:2282", "refsource": "REDHAT", "url": "https://access.redhat.com/errata/RHSA-2018:2282" }, { "name": "GLSA-201808-01", "refsource": "GENTOO", "url": "https://security.gentoo.org/glsa/201808-01" }, { "name": "https://support.apple.com/HT208696", "refsource": "CONFIRM", "url": "https://support.apple.com/HT208696" }, { "name": "https://support.apple.com/HT208693", "refsource": "CONFIRM", "url": "https://support.apple.com/HT208693" }, { "name": "DSA-4256", "refsource": "DEBIAN", "url": "https://www.debian.org/security/2018/dsa-4256" }, { "name": "https://support.apple.com/HT208694", "refsource": "CONFIRM", "url": "https://support.apple.com/HT208694" }, { "name": "104887", "refsource": "BID", "url": "http://www.securityfocus.com/bid/104887" }, { "name": "https://support.apple.com/HT208697", "refsource": "CONFIRM", "url": "https://support.apple.com/HT208697" }, { "name": "USN-3635-1", "refsource": "UBUNTU", "url": "https://usn.ubuntu.com/3635-1/" }, { "name": "https://support.apple.com/HT208695", "refsource": "CONFIRM", "url": "https://support.apple.com/HT208695" } ] } } } }, "cveMetadata": { "assignerOrgId": "286789f9-fbc2-4510-9f9a-43facdede74c", "assignerShortName": "apple", "cveId": "CVE-2018-4117", "datePublished": "2018-04-03T06:00:00", "dateReserved": "2018-01-02T00:00:00", "dateUpdated": "2024-08-05T05:04:29.828Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2018-4117\",\"sourceIdentifier\":\"product-security@apple.com\",\"published\":\"2018-04-03T06:29:04.937\",\"lastModified\":\"2018-11-09T17:58:22.260\",\"vulnStatus\":\"Analyzed\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the \\\"WebKit\\\" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.\"},{\"lang\":\"es\",\"value\":\"Se ha descubierto un problema en algunos productos Apple. Las versiones de iOS anteriores a la 11.3 se han visto afectadas. Se han visto afectadas las versiones de Safari anteriores a la 11.1, las versiones de iCloud anteriores a la 7.4 en Windows, las versiones de iTunes anteriores a la 12.7.4 en Windows y las versiones de watchOS anteriores a la 4.3. El problema afecta a la API fetch en el componente \\\"WebKit\\\". Permite que atacantes remotos omitan la Pol\u00edtica del Mismo Origen y obtengan informaci\u00f3n sensible mediante un sitio web manipulado.\"}],\"metrics\":{\"cvssMetricV30\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.0\",\"vectorString\":\"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"REQUIRED\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"NONE\",\"baseScore\":6.5,\"baseSeverity\":\"MEDIUM\"},\"exploitabilityScore\":2.8,\"impactScore\":3.6}],\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:N/AC:M/Au:N/C:P/I:N/A:N\",\"accessVector\":\"NETWORK\",\"accessComplexity\":\"MEDIUM\",\"authentication\":\"NONE\",\"confidentialityImpact\":\"PARTIAL\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"NONE\",\"baseScore\":4.3},\"baseSeverity\":\"MEDIUM\",\"exploitabilityScore\":8.6,\"impactScore\":2.9,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":true}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-200\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*\",\"versionEndExcluding\":\"11.1\",\"matchCriteriaId\":\"2683E773-F7E6-4B5A-B341-F34EC83368BB\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*\",\"versionEndExcluding\":\"11.3\",\"matchCriteriaId\":\"1AE9DC77-7A0A-47A4-9B85-6CCCFDE5B313\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*\",\"versionEndExcluding\":\"4.3\",\"matchCriteriaId\":\"360435F9-FC38-422B-8888-3656AF59A3BF\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:apple:icloud:*:*:*:*:*:*:*:*\",\"versionEndExcluding\":\"7.4\",\"matchCriteriaId\":\"C0720731-C892-498A-BFFE-D3DBCD096973\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"A2572D17-1DE6-457B-99CC-64AFD54487EA\"}]}]},{\"operator\":\"AND\",\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*\",\"versionEndExcluding\":\"12.7.4\",\"matchCriteriaId\":\"C7F515A1-9B93-4D6F-A269-CAEDEC1DD85E\"}]},{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":false,\"criteria\":\"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"A2572D17-1DE6-457B-99CC-64AFD54487EA\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:webkitgtk:webkitgtk\\\\+:*:*:*:*:*:*:*:*\",\"versionEndExcluding\":\"2.20.4\",\"matchCriteriaId\":\"33CC3DA1-F5EA-4276-B38B-5C68BA8EBCDA\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*\",\"matchCriteriaId\":\"F7016A2A-8365-4F1A-89A2-7A19F2BCAE5B\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"9070C9D8-A14A-467F-8253-33B966C16886\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"DEECE5FC-CACF-4496-A3E7-164736409252\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"EE249E1B-A1FD-4E08-AA71-A0E1F10FFE97\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"9BBCD86A-E6C7-4444-9D74-F861084090F0\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"E5ED5807-55B7-47C5-97A6-03233F4FBC3A\"}]}]}],\"references\":[{\"url\":\"http://www.securityfocus.com/bid/104887\",\"source\":\"product-security@apple.com\",\"tags\":[\"Third Party Advisory\",\"VDB Entry\"]},{\"url\":\"http://www.securitytracker.com/id/1040604\",\"source\":\"product-security@apple.com\",\"tags\":[\"Third Party Advisory\",\"VDB Entry\"]},{\"url\":\"https://access.redhat.com/errata/RHSA-2018:2282\",\"source\":\"product-security@apple.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://security.gentoo.org/glsa/201808-01\",\"source\":\"product-security@apple.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://security.gentoo.org/glsa/201808-04\",\"source\":\"product-security@apple.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://support.apple.com/HT208693\",\"source\":\"product-security@apple.com\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"https://support.apple.com/HT208694\",\"source\":\"product-security@apple.com\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"https://support.apple.com/HT208695\",\"source\":\"product-security@apple.com\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"https://support.apple.com/HT208696\",\"source\":\"product-security@apple.com\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"https://support.apple.com/HT208697\",\"source\":\"product-security@apple.com\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"https://usn.ubuntu.com/3635-1/\",\"source\":\"product-security@apple.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://www.debian.org/security/2018/dsa-4256\",\"source\":\"product-security@apple.com\",\"tags\":[\"Third Party Advisory\"]}]}}" } }
rhsa-2018_2282
Vulnerability from csaf_redhat
Notes
{ "document": { "aggregate_severity": { "namespace": "https://access.redhat.com/security/updates/classification/", "text": "Important" }, "category": "csaf_vex", "csaf_version": "2.0", "distribution": { "text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary.\n\nRed Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.", "title": "Topic" }, { "category": "general", "text": "Chromium is an open-source web browser, powered by WebKit (Blink).\n\nThis update upgrades Chromium to version 68.0.3440.75.\n\nSecurity Fix(es):\n\n* chromium-browser: Stack buffer overflow in Skia (CVE-2018-6153)\n\n* chromium-browser: Heap buffer overflow in WebGL (CVE-2018-6154)\n\n* chromium-browser: Use after free in WebRTC (CVE-2018-6155)\n\n* chromium-browser: Heap buffer overflow in WebRTC (CVE-2018-6156)\n\n* chromium-browser: Type confusion in WebRTC (CVE-2018-6157)\n\n* chromium-browser: Cross origin information disclosure in Service Workers (CVE-2018-6150)\n\n* chromium-browser: Bad cast in DevTools (CVE-2018-6151)\n\n* chromium-browser: Local file write in DevTools (CVE-2018-6152)\n\n* chromium-browser: Use after free in Blink (CVE-2018-6158)\n\n* chromium-browser: Same origin policy bypass in ServiceWorker (CVE-2018-6159)\n\n* chromium-browser: Same origin policy bypass in WebAudio (CVE-2018-6161)\n\n* chromium-browser: Heap buffer overflow in WebGL (CVE-2018-6162)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6163)\n\n* chromium-browser: Same origin policy bypass in ServiceWorker (CVE-2018-6164)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6165)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6166)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6167)\n\n* chromium-browser: CORS bypass in Blink (CVE-2018-6168)\n\n* chromium-browser: Permissions bypass in extension installation (CVE-2018-6169)\n\n* chromium-browser: Type confusion in PDFium (CVE-2018-6170)\n\n* chromium-browser: Use after free in WebBluetooth (CVE-2018-6171)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6172)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6173)\n\n* chromium-browser: Integer overflow in SwiftShader (CVE-2018-6174)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6175)\n\n* chromium-browser: Local user privilege escalation in Extensions (CVE-2018-6176)\n\n* chromium-browser: Cross origin information leak in Blink (CVE-2018-4117)\n\n* chromium-browser: Request privilege escalation in Extensions (CVE-2018-6044)\n\n* chromium-browser: Cross origin information leak in Blink (CVE-2018-6177)\n\n* chromium-browser: UI spoof in Extensions (CVE-2018-6178)\n\n* chromium-browser: Local file information leak in Extensions (CVE-2018-6179)\n\nFor more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.", "title": "Details" }, { "category": "legal_disclaimer", "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.", "title": "Terms of Use" } ], "publisher": { "category": "vendor", "contact_details": "https://access.redhat.com/security/team/contact/", "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat offerings.", "name": "Red Hat Product Security", "namespace": "https://www.redhat.com" }, "references": [ { "category": "self", "summary": "https://access.redhat.com/errata/RHSA-2018:2282", "url": "https://access.redhat.com/errata/RHSA-2018:2282" }, { "category": "external", "summary": "https://access.redhat.com/security/updates/classification/#important", "url": "https://access.redhat.com/security/updates/classification/#important" }, { "category": "external", "summary": "1608177", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608177" }, { "category": "external", "summary": "1608178", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608178" }, { "category": "external", "summary": "1608179", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608179" }, { "category": "external", "summary": "1608180", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608180" }, { "category": "external", "summary": "1608181", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608181" }, { "category": "external", "summary": "1608182", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608182" }, { "category": "external", "summary": "1608183", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608183" }, { "category": "external", "summary": "1608185", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608185" }, { "category": "external", "summary": "1608186", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608186" }, { "category": "external", "summary": "1608187", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608187" }, { "category": "external", "summary": "1608188", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608188" }, { "category": "external", "summary": "1608189", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608189" }, { "category": "external", "summary": "1608190", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608190" }, { "category": "external", "summary": "1608191", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608191" }, { "category": "external", "summary": "1608192", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608192" }, { "category": "external", "summary": "1608193", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608193" }, { "category": "external", "summary": "1608194", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608194" }, { "category": "external", "summary": "1608195", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608195" }, { "category": "external", "summary": "1608196", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608196" }, { "category": "external", "summary": "1608197", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608197" }, { "category": "external", "summary": "1608198", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608198" }, { "category": "external", "summary": "1608199", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608199" }, { "category": "external", "summary": "1608200", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608200" }, { "category": "external", "summary": "1608201", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608201" }, { "category": "external", "summary": "1608202", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608202" }, { "category": "external", "summary": "1608203", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608203" }, { "category": "external", "summary": "1608204", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608204" }, { "category": "external", "summary": "1608205", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608205" }, { "category": "external", "summary": "1608206", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608206" }, { "category": "external", "summary": "1608207", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608207" }, { "category": "external", "summary": "1608208", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608208" }, { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/data/csaf/v2/advisories/2018/rhsa-2018_2282.json" } ], "title": "Red Hat Security Advisory: chromium-browser security update", "tracking": { "current_release_date": "2024-09-13T15:08:28+00:00", "generator": { "date": "2024-09-13T15:08:28+00:00", "engine": { "name": "Red Hat SDEngine", "version": "3.33.3" } }, "id": "RHSA-2018:2282", "initial_release_date": "2018-07-30T15:10:23+00:00", "revision_history": [ { "date": "2018-07-30T15:10:23+00:00", "number": "1", "summary": "Initial version" }, { "date": "2018-07-30T15:10:23+00:00", "number": "2", "summary": "Last updated version" }, { "date": "2024-09-13T15:08:28+00:00", "number": "3", "summary": "Last generated version" } ], "status": "final", "version": "3" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_name", "name": "Red Hat Enterprise Linux Desktop Supplementary (v. 6)", "product": { "name": "Red Hat Enterprise Linux Desktop Supplementary (v. 6)", "product_id": "6Client-Supplementary-6.10.z", "product_identification_helper": { "cpe": "cpe:/a:redhat:rhel_extras:6" } } }, { "category": "product_name", "name": "Red Hat Enterprise Linux Server Supplementary (v. 6)", "product": { "name": "Red Hat Enterprise Linux Server Supplementary (v. 6)", "product_id": "6Server-Supplementary-6.10.z", "product_identification_helper": { "cpe": "cpe:/a:redhat:rhel_extras:6" } } }, { "category": "product_name", "name": "Red Hat Enterprise Linux Workstation Supplementary (v. 6)", "product": { "name": "Red Hat Enterprise Linux Workstation Supplementary (v. 6)", "product_id": "6Workstation-Supplementary-6.10.z", "product_identification_helper": { "cpe": "cpe:/a:redhat:rhel_extras:6" } } } ], "category": "product_family", "name": "Red Hat Enterprise Linux Supplementary" }, { "branches": [ { "category": "product_version", "name": "chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "product": { "name": "chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "product_id": "chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/chromium-browser@68.0.3440.75-1.el6_10?arch=x86_64" } } }, { "category": "product_version", "name": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "product": { "name": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "product_id": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "product_identification_helper": { "purl": "pkg:rpm/redhat/chromium-browser-debuginfo@68.0.3440.75-1.el6_10?arch=x86_64" } } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_version", "name": "chromium-browser-0:68.0.3440.75-1.el6_10.i686", "product": { "name": "chromium-browser-0:68.0.3440.75-1.el6_10.i686", "product_id": "chromium-browser-0:68.0.3440.75-1.el6_10.i686", "product_identification_helper": { "purl": "pkg:rpm/redhat/chromium-browser@68.0.3440.75-1.el6_10?arch=i686" } } }, { "category": "product_version", "name": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "product": { "name": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "product_id": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "product_identification_helper": { "purl": "pkg:rpm/redhat/chromium-browser-debuginfo@68.0.3440.75-1.el6_10?arch=i686" } } } ], "category": "architecture", "name": "i686" } ], "category": "vendor", "name": "Red Hat" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "chromium-browser-0:68.0.3440.75-1.el6_10.i686 as a component of Red Hat Enterprise Linux Desktop Supplementary (v. 6)", "product_id": "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686" }, "product_reference": "chromium-browser-0:68.0.3440.75-1.el6_10.i686", "relates_to_product_reference": "6Client-Supplementary-6.10.z" }, { "category": "default_component_of", "full_product_name": { "name": "chromium-browser-0:68.0.3440.75-1.el6_10.x86_64 as a component of Red Hat Enterprise Linux Desktop Supplementary (v. 6)", "product_id": "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64" }, "product_reference": "chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "relates_to_product_reference": "6Client-Supplementary-6.10.z" }, { "category": "default_component_of", "full_product_name": { "name": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686 as a component of Red Hat Enterprise Linux Desktop Supplementary (v. 6)", "product_id": "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686" }, "product_reference": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "relates_to_product_reference": "6Client-Supplementary-6.10.z" }, { "category": "default_component_of", "full_product_name": { "name": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64 as a component of Red Hat Enterprise Linux Desktop Supplementary (v. 6)", "product_id": "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" }, "product_reference": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "relates_to_product_reference": "6Client-Supplementary-6.10.z" }, { "category": "default_component_of", "full_product_name": { "name": "chromium-browser-0:68.0.3440.75-1.el6_10.i686 as a component of Red Hat Enterprise Linux Server Supplementary (v. 6)", "product_id": "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686" }, "product_reference": "chromium-browser-0:68.0.3440.75-1.el6_10.i686", "relates_to_product_reference": "6Server-Supplementary-6.10.z" }, { "category": "default_component_of", "full_product_name": { "name": "chromium-browser-0:68.0.3440.75-1.el6_10.x86_64 as a component of Red Hat Enterprise Linux Server Supplementary (v. 6)", "product_id": "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64" }, "product_reference": "chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "relates_to_product_reference": "6Server-Supplementary-6.10.z" }, { "category": "default_component_of", "full_product_name": { "name": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686 as a component of Red Hat Enterprise Linux Server Supplementary (v. 6)", "product_id": "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686" }, "product_reference": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "relates_to_product_reference": "6Server-Supplementary-6.10.z" }, { "category": "default_component_of", "full_product_name": { "name": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64 as a component of Red Hat Enterprise Linux Server Supplementary (v. 6)", "product_id": "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" }, "product_reference": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "relates_to_product_reference": "6Server-Supplementary-6.10.z" }, { "category": "default_component_of", "full_product_name": { "name": "chromium-browser-0:68.0.3440.75-1.el6_10.i686 as a component of Red Hat Enterprise Linux Workstation Supplementary (v. 6)", "product_id": "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686" }, "product_reference": "chromium-browser-0:68.0.3440.75-1.el6_10.i686", "relates_to_product_reference": "6Workstation-Supplementary-6.10.z" }, { "category": "default_component_of", "full_product_name": { "name": "chromium-browser-0:68.0.3440.75-1.el6_10.x86_64 as a component of Red Hat Enterprise Linux Workstation Supplementary (v. 6)", "product_id": "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64" }, "product_reference": "chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "relates_to_product_reference": "6Workstation-Supplementary-6.10.z" }, { "category": "default_component_of", "full_product_name": { "name": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686 as a component of Red Hat Enterprise Linux Workstation Supplementary (v. 6)", "product_id": "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686" }, "product_reference": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "relates_to_product_reference": "6Workstation-Supplementary-6.10.z" }, { "category": "default_component_of", "full_product_name": { "name": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64 as a component of Red Hat Enterprise Linux Workstation Supplementary (v. 6)", "product_id": "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" }, "product_reference": "chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "relates_to_product_reference": "6Workstation-Supplementary-6.10.z" } ] }, "vulnerabilities": [ { "cve": "CVE-2018-4117", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608205" } ], "notes": [ { "category": "description", "text": "An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the \"WebKit\" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Cross origin information leak in Blink", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-4117" }, { "category": "external", "summary": "RHBZ#1608205", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608205" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-4117", "url": "https://www.cve.org/CVERecord?id=CVE-2018-4117" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-4117", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-4117" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Low" } ], "title": "chromium-browser: Cross origin information leak in Blink" }, { "cve": "CVE-2018-6150", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608206" } ], "notes": [ { "category": "description", "text": "Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Cross origin information disclosure in Service Workers", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6150" }, { "category": "external", "summary": "RHBZ#1608206", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608206" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6150", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6150" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6150", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6150" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: Cross origin information disclosure in Service Workers" }, { "cve": "CVE-2018-6151", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608207" } ], "notes": [ { "category": "description", "text": "Bad cast in DevTools in Google Chrome on Win, Linux, Mac, Chrome OS prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Bad cast in DevTools", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6151" }, { "category": "external", "summary": "RHBZ#1608207", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608207" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6151", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6151" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6151", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6151" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: Bad cast in DevTools" }, { "cve": "CVE-2018-6152", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608208" } ], "notes": [ { "category": "description", "text": "The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page and user interaction.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Local file write in DevTools", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6152" }, { "category": "external", "summary": "RHBZ#1608208", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608208" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6152", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6152" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6152", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6152" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: Local file write in DevTools" }, { "cve": "CVE-2018-6153", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608177" } ], "notes": [ { "category": "description", "text": "A precision error in Skia in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Stack buffer overflow in Skia", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6153" }, { "category": "external", "summary": "RHBZ#1608177", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608177" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6153", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6153" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6153", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6153" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Important" } ], "title": "chromium-browser: Stack buffer overflow in Skia" }, { "cve": "CVE-2018-6154", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608178" } ], "notes": [ { "category": "description", "text": "Insufficient data validation in WebGL in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Heap buffer overflow in WebGL", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6154" }, { "category": "external", "summary": "RHBZ#1608178", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608178" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6154", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6154" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6154", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6154" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Important" } ], "title": "chromium-browser: Heap buffer overflow in WebGL" }, { "cve": "CVE-2018-6155", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608179" } ], "notes": [ { "category": "description", "text": "Incorrect handling of frames in the VP8 parser in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Use after free in WebRTC", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6155" }, { "category": "external", "summary": "RHBZ#1608179", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608179" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6155", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6155" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6155", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6155" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Important" } ], "title": "chromium-browser: Use after free in WebRTC" }, { "cve": "CVE-2018-6156", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608180" } ], "notes": [ { "category": "description", "text": "Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Heap buffer overflow in WebRTC", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6156" }, { "category": "external", "summary": "RHBZ#1608180", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608180" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6156", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6156" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6156", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6156" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Important" } ], "title": "chromium-browser: Heap buffer overflow in WebRTC" }, { "cve": "CVE-2018-6157", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608181" } ], "notes": [ { "category": "description", "text": "Type confusion in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Type confusion in WebRTC", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6157" }, { "category": "external", "summary": "RHBZ#1608181", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608181" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6157", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6157" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6157", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6157" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Important" } ], "title": "chromium-browser: Type confusion in WebRTC" }, { "cve": "CVE-2018-6158", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608182" } ], "notes": [ { "category": "description", "text": "A race condition in Oilpan in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Use after free in Blink", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6158" }, { "category": "external", "summary": "RHBZ#1608182", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608182" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6158", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6158" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6158", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6158" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: Use after free in Blink" }, { "cve": "CVE-2018-6159", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608183" } ], "notes": [ { "category": "description", "text": "Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Same origin policy bypass in ServiceWorker", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6159" }, { "category": "external", "summary": "RHBZ#1608183", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608183" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6159", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6159" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6159", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6159" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: Same origin policy bypass in ServiceWorker" }, { "cve": "CVE-2018-6161", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608185" } ], "notes": [ { "category": "description", "text": "Insufficient policy enforcement in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to bypass same origin policy via a crafted HTML page.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Same origin policy bypass in WebAudio", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6161" }, { "category": "external", "summary": "RHBZ#1608185", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608185" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6161", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6161" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6161", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6161" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: Same origin policy bypass in WebAudio" }, { "cve": "CVE-2018-6162", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608186" } ], "notes": [ { "category": "description", "text": "Improper deserialization in WebGL in Google Chrome on Mac prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Heap buffer overflow in WebGL", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6162" }, { "category": "external", "summary": "RHBZ#1608186", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608186" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6162", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6162" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6162", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6162" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: Heap buffer overflow in WebGL" }, { "cve": "CVE-2018-6163", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608187" } ], "notes": [ { "category": "description", "text": "Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: URL spoof in Omnibox", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6163" }, { "category": "external", "summary": "RHBZ#1608187", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608187" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6163", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6163" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6163", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6163" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: URL spoof in Omnibox" }, { "cve": "CVE-2018-6164", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608188" } ], "notes": [ { "category": "description", "text": "Insufficient origin checks for CSS content in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Same origin policy bypass in ServiceWorker", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6164" }, { "category": "external", "summary": "RHBZ#1608188", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608188" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6164", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6164" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6164", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6164" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: Same origin policy bypass in ServiceWorker" }, { "cve": "CVE-2018-6165", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608189" } ], "notes": [ { "category": "description", "text": "Incorrect handling of reloads in Navigation in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: URL spoof in Omnibox", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6165" }, { "category": "external", "summary": "RHBZ#1608189", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608189" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6165", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6165" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6165", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6165" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: URL spoof in Omnibox" }, { "cve": "CVE-2018-6166", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608190" } ], "notes": [ { "category": "description", "text": "Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: URL spoof in Omnibox", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6166" }, { "category": "external", "summary": "RHBZ#1608190", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608190" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6166", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6166" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6166", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6166" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: URL spoof in Omnibox" }, { "cve": "CVE-2018-6167", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608191" } ], "notes": [ { "category": "description", "text": "Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: URL spoof in Omnibox", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6167" }, { "category": "external", "summary": "RHBZ#1608191", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608191" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6167", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6167" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6167", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6167" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: URL spoof in Omnibox" }, { "cve": "CVE-2018-6168", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608192" } ], "notes": [ { "category": "description", "text": "Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: CORS bypass in Blink", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6168" }, { "category": "external", "summary": "RHBZ#1608192", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608192" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6168", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6168" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6168", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6168" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: CORS bypass in Blink" }, { "cve": "CVE-2018-6169", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608193" } ], "notes": [ { "category": "description", "text": "Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of an unwanted extension via a crafted HTML page.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Permissions bypass in extension installation", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6169" }, { "category": "external", "summary": "RHBZ#1608193", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608193" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6169", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6169" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6169", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6169" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: Permissions bypass in extension installation" }, { "cve": "CVE-2018-6170", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608194" } ], "notes": [ { "category": "description", "text": "A bad cast in PDFium in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Type confusion in PDFium", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6170" }, { "category": "external", "summary": "RHBZ#1608194", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608194" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6170", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6170" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6170", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6170" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: Type confusion in PDFium" }, { "cve": "CVE-2018-6171", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608195" } ], "notes": [ { "category": "description", "text": "Use after free in Bluetooth in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Use after free in WebBluetooth", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6171" }, { "category": "external", "summary": "RHBZ#1608195", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608195" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6171", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6171" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6171", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6171" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: Use after free in WebBluetooth" }, { "cve": "CVE-2018-6172", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608196" } ], "notes": [ { "category": "description", "text": "Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: URL spoof in Omnibox", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6172" }, { "category": "external", "summary": "RHBZ#1608196", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608196" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6172", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6172" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6172", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6172" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: URL spoof in Omnibox" }, { "cve": "CVE-2018-6173", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608197" } ], "notes": [ { "category": "description", "text": "Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: URL spoof in Omnibox", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6173" }, { "category": "external", "summary": "RHBZ#1608197", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608197" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6173", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6173" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6173", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6173" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: URL spoof in Omnibox" }, { "cve": "CVE-2018-6174", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608198" } ], "notes": [ { "category": "description", "text": "Integer overflows in Swiftshader in Google Chrome prior to 68.0.3440.75 potentially allowed a remote attacker to execute arbitrary code via a crafted HTML page.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Integer overflow in SwiftShader", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6174" }, { "category": "external", "summary": "RHBZ#1608198", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608198" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6174", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6174" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6174", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6174" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: Integer overflow in SwiftShader" }, { "cve": "CVE-2018-6175", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608199" } ], "notes": [ { "category": "description", "text": "Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: URL spoof in Omnibox", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6175" }, { "category": "external", "summary": "RHBZ#1608199", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608199" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6175", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6175" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6175", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6175" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: URL spoof in Omnibox" }, { "cve": "CVE-2018-6176", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608200" } ], "notes": [ { "category": "description", "text": "Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted Chrome Extension.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Local user privilege escalation in Extensions", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6176" }, { "category": "external", "summary": "RHBZ#1608200", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608200" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6176", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6176" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6176", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6176" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Moderate" } ], "title": "chromium-browser: Local user privilege escalation in Extensions" }, { "cve": "CVE-2018-6177", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608201" } ], "notes": [ { "category": "description", "text": "Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Cross origin information leak in Blink", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6177" }, { "category": "external", "summary": "RHBZ#1608201", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608201" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6177", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6177" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6177", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6177" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 4.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Low" } ], "title": "chromium-browser: Cross origin information leak in Blink" }, { "cve": "CVE-2018-6178", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608202" } ], "notes": [ { "category": "description", "text": "Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: UI spoof in Extensions", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6178" }, { "category": "external", "summary": "RHBZ#1608202", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608202" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6178", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6178" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6178", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6178" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 4.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Low" } ], "title": "chromium-browser: UI spoof in Extensions" }, { "cve": "CVE-2018-6179", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608203" } ], "notes": [ { "category": "description", "text": "Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Local file information leak in Extensions", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-6179" }, { "category": "external", "summary": "RHBZ#1608203", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608203" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-6179", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6179" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-6179", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-6179" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 4.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Low" } ], "title": "chromium-browser: Local file information leak in Extensions" }, { "cve": "CVE-2018-16064", "discovery_date": "2018-07-25T00:00:00+00:00", "ids": [ { "system_name": "Red Hat Bugzilla ID", "text": "1608204" } ], "notes": [ { "category": "description", "text": "Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.", "title": "Vulnerability description" }, { "category": "summary", "text": "chromium-browser: Request privilege escalation in Extensions", "title": "Vulnerability summary" }, { "category": "general", "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.", "title": "CVSS score applicability" } ], "product_status": { "fixed": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] }, "references": [ { "category": "self", "summary": "Canonical URL", "url": "https://access.redhat.com/security/cve/CVE-2018-16064" }, { "category": "external", "summary": "RHBZ#1608204", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1608204" }, { "category": "external", "summary": "https://www.cve.org/CVERecord?id=CVE-2018-16064", "url": "https://www.cve.org/CVERecord?id=CVE-2018-16064" }, { "category": "external", "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-16064", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-16064" }, { "category": "external", "summary": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html", "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" } ], "release_date": "2018-07-24T00:00:00+00:00", "remediations": [ { "category": "vendor_fix", "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to take effect.", "product_ids": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ], "restart_required": { "category": "none" }, "url": "https://access.redhat.com/errata/RHSA-2018:2282" } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 4.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Client-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Server-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-0:68.0.3440.75-1.el6_10.x86_64", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.i686", "6Workstation-Supplementary-6.10.z:chromium-browser-debuginfo-0:68.0.3440.75-1.el6_10.x86_64" ] } ], "threats": [ { "category": "impact", "details": "Low" } ], "title": "chromium-browser: Request privilege escalation in Extensions" } ] }
var-201804-1177
Vulnerability from variot
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. Apple iOS, iCloud for Windows, iTunes for Windows, Safari, and tvOS are all products of the American company Apple (Apple). Apple iOS is an operating system developed for mobile devices; Safari is a web browser that comes with the Mac OS X and iOS operating systems by default. WebKit is an open source web browser engine developed by the KDE community and is currently used by browsers such as Apple Safari and Google Chrome. ------------------------------------------------------------------------ WebKitGTK+ Security Advisory WSA-2018-0003
Date reported : April 04, 2018 Advisory ID : WSA-2018-0003 Advisory URL : https://webkitgtk.org/security/WSA-2018-0003.html CVE identifiers : CVE-2018-4101, CVE-2018-4113, CVE-2018-4114, CVE-2018-4117, CVE-2018-4118, CVE-2018-4119, CVE-2018-4120, CVE-2018-4122, CVE-2018-4125, CVE-2018-4127, CVE-2018-4128, CVE-2018-4129, CVE-2018-4133, CVE-2018-4146, CVE-2018-4161, CVE-2018-4162, CVE-2018-4163, CVE-2018-4165.
Several vulnerabilities were discovered in WebKitGTK+. Credit to Yuan Deng of Ant-financial Light-Year Security Lab. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to OSS-Fuzz. Impact: Unexpected interaction with indexing types causing an ASSERT failure. Description: An array indexing issue existed in the handling of a function in JavaScriptCore. This issue was addressed through improved checks. Credit to OSS-Fuzz. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to an anonymous researcher. Impact: A malicious website may exfiltrate data cross-origin. This was addressed through improved input validation. Credit to Jun Kokatsu (@shhnjk). Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to an anonymous researcher working with Trend Microys Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to Hanming Zhang (@4shitak4) of Qihoo 360 Vulcan Team. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to WanderingGlitch of Trend Micro's Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to WanderingGlitch of Trend Micro's Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to an anonymous researcher working with Trend Microys Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to Zach Markley. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to likemeng of Baidu Security Lab working with Trend Micro's Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to Anton Lopanitsyn of Wallarm, Linus Sarud of Detectify (detectify.com), Yuji Tounai of NTT Communications Corporation. Impact: Visiting a maliciously crafted website may lead to a cross- site scripting attack. Description: A cross-site scripting issue existed in WebKit. This issue was addressed with improved URL validation. Credit to OSS-Fuzz. Impact: Processing maliciously crafted web content may lead to a denial of service. Description: A memory corruption issue was addressed through improved input validation. Credit to WanderingGlitch of Trend Micro's Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to WanderingGlitch of Trend Micro's Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to WanderingGlitch of Trend Micro's Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling. Credit to Hanming Zhang (@4shitak4) of Qihoo 360 Vulcan Team. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
We recommend updating to the last stable version of WebKitGTK+. It is the best way of ensuring that you are running a safe version of WebKitGTK+. Please check our website for information about the last stable releases.
Further information about WebKitGTK+ Security Advisories can be found at: https://webkitgtk.org/security.html
The WebKitGTK+ team, April 04, 2018 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512
APPLE-SA-2018-3-29-2 watchOS 4.3
watchOS 4.3 is now available and addresses the following:
CoreFoundation Available for: All Apple Watch models Impact: An application may be able to gain elevated privileges Description: A race condition was addressed with additional validation. CVE-2018-4142: Robin Leroy of Google Switzerland GmbH
File System Events Available for: All Apple Watch models Impact: An application may be able to gain elevated privileges Description: A race condition was addressed with additional validation. CVE-2018-4104: The UK's National Cyber Security Centre (NCSC)
Kernel Available for: All Apple Watch models Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2018-4143: derrek (@derrekr6)
NSURLSession Available for: All Apple Watch models Impact: An application may be able to gain elevated privileges Description: A race condition was addressed with additional validation. CVE-2018-4166: Samuel GroA (@5aelo)
Quick Look Available for: All Apple Watch models Impact: An application may be able to gain elevated privileges Description: A race condition was addressed with additional validation. CVE-2018-4157: Samuel GroA (@5aelo)
Security Available for: All Apple Watch models Impact: A malicious application may be able to elevate privileges Description: A buffer overflow was addressed with improved size validation. CVE-2018-4144: Abraham Masri (@cheesecakeufo)
System Preferences Available for: All Apple Watch models Impact: A configuration profile may incorrectly remain in effect after removal Description: An issue existed in CFPreferences. CVE-2018-4117: an anonymous researcher, an anonymous researcher
Installation note:
Instructions on how to update your Apple Watch software are available at https://support.apple.com/kb/HT204641
To check the version on your Apple Watch, open the Apple Watch app on your iPhone and select "My Watch > General > About".
Alternatively, on your watch, select "My Watch > General > About". ========================================================================== Ubuntu Security Notice USN-3635-1 April 30, 2018
webkit2gtk vulnerabilities
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 17.10
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in WebKitGTK+.
Software Description: - webkit2gtk: Web content engine library for GTK+
Details:
A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 17.10: libjavascriptcoregtk-4.0-18 2.20.1-0ubuntu0.17.10.1 libwebkit2gtk-4.0-37 2.20.1-0ubuntu0.17.10.1
Ubuntu 16.04 LTS: libjavascriptcoregtk-4.0-18 2.20.1-0ubuntu0.16.04.1 libwebkit2gtk-4.0-37 2.20.1-0ubuntu0.16.04.1
This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any applications that use WebKitGTK+, such as Epiphany, to make all the necessary changes. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2018:2282-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2018:2282 Issue date: 2018-07-30 CVE Names: CVE-2018-4117 CVE-2018-6044 CVE-2018-6150 CVE-2018-6151 CVE-2018-6152 CVE-2018-6153 CVE-2018-6154 CVE-2018-6155 CVE-2018-6156 CVE-2018-6157 CVE-2018-6158 CVE-2018-6159 CVE-2018-6161 CVE-2018-6162 CVE-2018-6163 CVE-2018-6164 CVE-2018-6165 CVE-2018-6166 CVE-2018-6167 CVE-2018-6168 CVE-2018-6169 CVE-2018-6170 CVE-2018-6171 CVE-2018-6172 CVE-2018-6173 CVE-2018-6174 CVE-2018-6175 CVE-2018-6176 CVE-2018-6177 CVE-2018-6178 CVE-2018-6179 ==================================================================== 1. Summary:
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
- Relevant releases/architectures:
Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64
- Description:
Chromium is an open-source web browser, powered by WebKit (Blink).
This update upgrades Chromium to version 68.0.3440.75.
Security Fix(es):
-
chromium-browser: Stack buffer overflow in Skia (CVE-2018-6153)
-
chromium-browser: Heap buffer overflow in WebGL (CVE-2018-6154)
-
chromium-browser: Use after free in WebRTC (CVE-2018-6155)
-
chromium-browser: Heap buffer overflow in WebRTC (CVE-2018-6156)
-
chromium-browser: Type confusion in WebRTC (CVE-2018-6157)
-
chromium-browser: Cross origin information disclosure in Service Workers (CVE-2018-6150)
-
chromium-browser: Bad cast in DevTools (CVE-2018-6151)
-
chromium-browser: Local file write in DevTools (CVE-2018-6152)
-
chromium-browser: Use after free in Blink (CVE-2018-6158)
-
chromium-browser: Same origin policy bypass in ServiceWorker (CVE-2018-6159)
-
chromium-browser: Same origin policy bypass in WebAudio (CVE-2018-6161)
-
chromium-browser: Heap buffer overflow in WebGL (CVE-2018-6162)
-
chromium-browser: URL spoof in Omnibox (CVE-2018-6163)
-
chromium-browser: Same origin policy bypass in ServiceWorker (CVE-2018-6164)
-
chromium-browser: URL spoof in Omnibox (CVE-2018-6165)
-
chromium-browser: URL spoof in Omnibox (CVE-2018-6166)
-
chromium-browser: URL spoof in Omnibox (CVE-2018-6167)
-
chromium-browser: CORS bypass in Blink (CVE-2018-6168)
-
chromium-browser: Permissions bypass in extension installation (CVE-2018-6169)
-
chromium-browser: Type confusion in PDFium (CVE-2018-6170)
-
chromium-browser: Use after free in WebBluetooth (CVE-2018-6171)
-
chromium-browser: URL spoof in Omnibox (CVE-2018-6172)
-
chromium-browser: URL spoof in Omnibox (CVE-2018-6173)
-
chromium-browser: Integer overflow in SwiftShader (CVE-2018-6174)
-
chromium-browser: URL spoof in Omnibox (CVE-2018-6175)
-
chromium-browser: Local user privilege escalation in Extensions (CVE-2018-6176)
-
chromium-browser: Cross origin information leak in Blink (CVE-2018-4117)
-
chromium-browser: Request privilege escalation in Extensions (CVE-2018-6044)
-
chromium-browser: Cross origin information leak in Blink (CVE-2018-6177)
-
chromium-browser: UI spoof in Extensions (CVE-2018-6178)
-
chromium-browser: Local file information leak in Extensions (CVE-2018-6179)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
- Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the update, Chromium must be restarted for the changes to take effect.
- Bugs fixed (https://bugzilla.redhat.com/):
1608177 - CVE-2018-6153 chromium-browser: Stack buffer overflow in Skia 1608178 - CVE-2018-6154 chromium-browser: Heap buffer overflow in WebGL 1608179 - CVE-2018-6155 chromium-browser: Use after free in WebRTC 1608180 - CVE-2018-6156 chromium-browser: Heap buffer overflow in WebRTC 1608181 - CVE-2018-6157 chromium-browser: Type confusion in WebRTC 1608182 - CVE-2018-6158 chromium-browser: Use after free in Blink 1608183 - CVE-2018-6159 chromium-browser: Same origin policy bypass in ServiceWorker 1608185 - CVE-2018-6161 chromium-browser: Same origin policy bypass in WebAudio 1608186 - CVE-2018-6162 chromium-browser: Heap buffer overflow in WebGL 1608187 - CVE-2018-6163 chromium-browser: URL spoof in Omnibox 1608188 - CVE-2018-6164 chromium-browser: Same origin policy bypass in ServiceWorker 1608189 - CVE-2018-6165 chromium-browser: URL spoof in Omnibox 1608190 - CVE-2018-6166 chromium-browser: URL spoof in Omnibox 1608191 - CVE-2018-6167 chromium-browser: URL spoof in Omnibox 1608192 - CVE-2018-6168 chromium-browser: CORS bypass in Blink 1608193 - CVE-2018-6169 chromium-browser: Permissions bypass in extension installation 1608194 - CVE-2018-6170 chromium-browser: Type confusion in PDFium 1608195 - CVE-2018-6171 chromium-browser: Use after free in WebBluetooth 1608196 - CVE-2018-6172 chromium-browser: URL spoof in Omnibox 1608197 - CVE-2018-6173 chromium-browser: URL spoof in Omnibox 1608198 - CVE-2018-6174 chromium-browser: Integer overflow in SwiftShader 1608199 - CVE-2018-6175 chromium-browser: URL spoof in Omnibox 1608200 - CVE-2018-6176 chromium-browser: Local user privilege escalation in Extensions 1608201 - CVE-2018-6177 chromium-browser: Cross origin information leak in Blink 1608202 - CVE-2018-6178 chromium-browser: UI spoof in Extensions 1608203 - CVE-2018-6179 chromium-browser: Local file information leak in Extensions 1608204 - CVE-2018-6044 chromium-browser: Request privilege escalation in Extensions 1608205 - CVE-2018-4117 chromium-browser: Cross origin information leak in Blink 1608206 - CVE-2018-6150 chromium-browser: Cross origin information disclosure in Service Workers 1608207 - CVE-2018-6151 chromium-browser: Bad cast in DevTools 1608208 - CVE-2018-6152 chromium-browser: Local file write in DevTools
- Package List:
Red Hat Enterprise Linux Desktop Supplementary (v. 6):
i386: chromium-browser-68.0.3440.75-1.el6_10.i686.rpm chromium-browser-debuginfo-68.0.3440.75-1.el6_10.i686.rpm
x86_64: chromium-browser-68.0.3440.75-1.el6_10.x86_64.rpm chromium-browser-debuginfo-68.0.3440.75-1.el6_10.x86_64.rpm
Red Hat Enterprise Linux Server Supplementary (v. 6):
i386: chromium-browser-68.0.3440.75-1.el6_10.i686.rpm chromium-browser-debuginfo-68.0.3440.75-1.el6_10.i686.rpm
x86_64: chromium-browser-68.0.3440.75-1.el6_10.x86_64.rpm chromium-browser-debuginfo-68.0.3440.75-1.el6_10.x86_64.rpm
Red Hat Enterprise Linux Workstation Supplementary (v. 6):
i386: chromium-browser-68.0.3440.75-1.el6_10.i686.rpm chromium-browser-debuginfo-68.0.3440.75-1.el6_10.i686.rpm
x86_64: chromium-browser-68.0.3440.75-1.el6_10.x86_64.rpm chromium-browser-debuginfo-68.0.3440.75-1.el6_10.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/
- References:
https://access.redhat.com/security/cve/CVE-2018-4117 https://access.redhat.com/security/cve/CVE-2018-6044 https://access.redhat.com/security/cve/CVE-2018-6150 https://access.redhat.com/security/cve/CVE-2018-6151 https://access.redhat.com/security/cve/CVE-2018-6152 https://access.redhat.com/security/cve/CVE-2018-6153 https://access.redhat.com/security/cve/CVE-2018-6154 https://access.redhat.com/security/cve/CVE-2018-6155 https://access.redhat.com/security/cve/CVE-2018-6156 https://access.redhat.com/security/cve/CVE-2018-6157 https://access.redhat.com/security/cve/CVE-2018-6158 https://access.redhat.com/security/cve/CVE-2018-6159 https://access.redhat.com/security/cve/CVE-2018-6161 https://access.redhat.com/security/cve/CVE-2018-6162 https://access.redhat.com/security/cve/CVE-2018-6163 https://access.redhat.com/security/cve/CVE-2018-6164 https://access.redhat.com/security/cve/CVE-2018-6165 https://access.redhat.com/security/cve/CVE-2018-6166 https://access.redhat.com/security/cve/CVE-2018-6167 https://access.redhat.com/security/cve/CVE-2018-6168 https://access.redhat.com/security/cve/CVE-2018-6169 https://access.redhat.com/security/cve/CVE-2018-6170 https://access.redhat.com/security/cve/CVE-2018-6171 https://access.redhat.com/security/cve/CVE-2018-6172 https://access.redhat.com/security/cve/CVE-2018-6173 https://access.redhat.com/security/cve/CVE-2018-6174 https://access.redhat.com/security/cve/CVE-2018-6175 https://access.redhat.com/security/cve/CVE-2018-6176 https://access.redhat.com/security/cve/CVE-2018-6177 https://access.redhat.com/security/cve/CVE-2018-6178 https://access.redhat.com/security/cve/CVE-2018-6179 https://access.redhat.com/security/updates/classification/#important
- Contact:
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/
Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1
iQIVAwUBW18qZtzjgjWX9erEAQhZ2w/+O2aOCGCk2DIKqwT/ErfmvasFiNz7u8I1 +yPMYTQ1NFrs8cjt/ym7PH50aFOMS/YO3n/YL5ROLzoDW/PqXvJdxvi9opWG958V ftc20yBBa4EdJExqkKQYefxg9qD4emt6jkVBzSd/xZ3XcF50oKBG0m1aEPmCzM/G +o3ohQPiKgAMXJMtqTvSXxy1dV0LuoFOWYS6FPrO2F2MzY0Vd8/GXP1bnxqqqYxT ohA0f2yoPWVGzQQBRGCeHvTjv6Mt0PdGejKAoUxptgXenOQ9xAyRBuhSBkvBXAAN 3m+pEmWpHdOdEWoiIx07QcaH408ji+gs2oMSybS16PUwe9VsuOOJBOgFSLjxdb3d bzUjIKZHHscjxA1KIVtAx2JdqTLUKlSjSvaaZxa5d/wFq2UticBM8+EotuIOdE5J 6BVLVX+0GUCizPNbgC2f4i2G3xd60uiym9KP70Z7X+W7vMl9qXcab+GOJCAufwY8 +dfchywwsT19FdQLBJEjKPm7b33FNdr0oLvg6D5RK4pdJMYiEXoCt6ElLBBQzSEA 3vXsagWAaeDEBsLeDNapkLh1BHUx86iMVLGUtiwFgbtAXg7Jbz82AHZmtwT1bf6I KR7aOFFs2zKjRSuQDQZlOPNQVCt04+NbMZYEw6cHIT/+wX7ZrXaNZp+4tTo9gnOf R1+VLpZrH1Q=jHL1 -----END PGP SIGNATURE-----
-- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201808-01
https://security.gentoo.org/
Severity: Normal Title: Chromium, Google Chrome: Multiple vulnerabilities Date: August 22, 2018 Bugs: #657376, #662436 ID: 201808-01
Synopsis
Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which allows remote attackers to escalate privileges.
Background
Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.
Google Chrome is one fast, simple, and secure browser for all your devices.
Affected packages
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 www-client/chromium < 68.0.3440.75 >= 68.0.3440.75 2 www-client/google-chrome < 68.0.3440.75 >= 68.0.3440.75 ------------------------------------------------------------------- 2 affected packages
Description
Multiple vulnerabilities have been discovered in Chromium and Google Chrome. Please review the referenced CVE identifiers and Google Chrome Releases for details.
Workaround
There is no known workaround at this time.
Resolution
All Chromium users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot -v ">=www-client/chromium-68.0.3440.75"
All Google Chrome users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot -v ">=www-client/google-chrome-68.0.3440.75"
References
[ 1 ] CVE-2018-4117 https://nvd.nist.gov/vuln/detail/CVE-2018-4117 [ 2 ] CVE-2018-6044 https://nvd.nist.gov/vuln/detail/CVE-2018-6044 [ 3 ] CVE-2018-6150 https://nvd.nist.gov/vuln/detail/CVE-2018-6150 [ 4 ] CVE-2018-6151 https://nvd.nist.gov/vuln/detail/CVE-2018-6151 [ 5 ] CVE-2018-6152 https://nvd.nist.gov/vuln/detail/CVE-2018-6152 [ 6 ] CVE-2018-6153 https://nvd.nist.gov/vuln/detail/CVE-2018-6153 [ 7 ] CVE-2018-6154 https://nvd.nist.gov/vuln/detail/CVE-2018-6154 [ 8 ] CVE-2018-6155 https://nvd.nist.gov/vuln/detail/CVE-2018-6155 [ 9 ] CVE-2018-6156 https://nvd.nist.gov/vuln/detail/CVE-2018-6156 [ 10 ] CVE-2018-6157 https://nvd.nist.gov/vuln/detail/CVE-2018-6157 [ 11 ] CVE-2018-6158 https://nvd.nist.gov/vuln/detail/CVE-2018-6158 [ 12 ] CVE-2018-6159 https://nvd.nist.gov/vuln/detail/CVE-2018-6159 [ 13 ] CVE-2018-6160 https://nvd.nist.gov/vuln/detail/CVE-2018-6160 [ 14 ] CVE-2018-6161 https://nvd.nist.gov/vuln/detail/CVE-2018-6161 [ 15 ] CVE-2018-6162 https://nvd.nist.gov/vuln/detail/CVE-2018-6162 [ 16 ] CVE-2018-6163 https://nvd.nist.gov/vuln/detail/CVE-2018-6163 [ 17 ] CVE-2018-6164 https://nvd.nist.gov/vuln/detail/CVE-2018-6164 [ 18 ] CVE-2018-6165 https://nvd.nist.gov/vuln/detail/CVE-2018-6165 [ 19 ] CVE-2018-6166 https://nvd.nist.gov/vuln/detail/CVE-2018-6166 [ 20 ] CVE-2018-6167 https://nvd.nist.gov/vuln/detail/CVE-2018-6167 [ 21 ] CVE-2018-6168 https://nvd.nist.gov/vuln/detail/CVE-2018-6168 [ 22 ] CVE-2018-6169 https://nvd.nist.gov/vuln/detail/CVE-2018-6169 [ 23 ] CVE-2018-6170 https://nvd.nist.gov/vuln/detail/CVE-2018-6170 [ 24 ] CVE-2018-6171 https://nvd.nist.gov/vuln/detail/CVE-2018-6171 [ 25 ] CVE-2018-6172 https://nvd.nist.gov/vuln/detail/CVE-2018-6172 [ 26 ] CVE-2018-6173 https://nvd.nist.gov/vuln/detail/CVE-2018-6173 [ 27 ] CVE-2018-6174 https://nvd.nist.gov/vuln/detail/CVE-2018-6174 [ 28 ] CVE-2018-6175 https://nvd.nist.gov/vuln/detail/CVE-2018-6175 [ 29 ] CVE-2018-6176 https://nvd.nist.gov/vuln/detail/CVE-2018-6176 [ 30 ] CVE-2018-6177 https://nvd.nist.gov/vuln/detail/CVE-2018-6177 [ 31 ] CVE-2018-6178 https://nvd.nist.gov/vuln/detail/CVE-2018-6178 [ 32 ] CVE-2018-6179 https://nvd.nist.gov/vuln/detail/CVE-2018-6179 [ 33 ] CVE-2108-6150 https://nvd.nist.gov/vuln/detail/CVE-2108-6150 [ 34 ] Google Chrome 68.0.3440.75 release announcement
https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html
Availability
This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
https://security.gentoo.org/glsa/201808-01
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.
License
Copyright 2018 Gentoo Foundation, Inc; referenced text belongs to its owner(s).
The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
Show details on source website{ "@context": { "@vocab": "https://www.variotdbs.pl/ref/VARIoTentry#", "affected_products": { "@id": "https://www.variotdbs.pl/ref/affected_products" }, "configurations": { "@id": "https://www.variotdbs.pl/ref/configurations" }, "credits": { "@id": "https://www.variotdbs.pl/ref/credits" }, "cvss": { "@id": "https://www.variotdbs.pl/ref/cvss/" }, "description": { "@id": "https://www.variotdbs.pl/ref/description/" }, "exploit_availability": { "@id": "https://www.variotdbs.pl/ref/exploit_availability/" }, "external_ids": { "@id": "https://www.variotdbs.pl/ref/external_ids/" }, "iot": { "@id": "https://www.variotdbs.pl/ref/iot/" }, "iot_taxonomy": { "@id": "https://www.variotdbs.pl/ref/iot_taxonomy/" }, "patch": { "@id": "https://www.variotdbs.pl/ref/patch/" }, "problemtype_data": { "@id": "https://www.variotdbs.pl/ref/problemtype_data/" }, "references": { "@id": "https://www.variotdbs.pl/ref/references/" }, "sources": { "@id": "https://www.variotdbs.pl/ref/sources/" }, "sources_release_date": { "@id": "https://www.variotdbs.pl/ref/sources_release_date/" }, "sources_update_date": { "@id": "https://www.variotdbs.pl/ref/sources_update_date/" }, "threat_type": { "@id": "https://www.variotdbs.pl/ref/threat_type/" }, "title": { "@id": "https://www.variotdbs.pl/ref/title/" }, "type": { "@id": "https://www.variotdbs.pl/ref/type/" } }, "@id": "https://www.variotdbs.pl/vuln/VAR-201804-1177", "affected_products": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/affected_products#", "data": { "@container": "@list" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" }, "@id": "https://www.variotdbs.pl/ref/sources" } }, "data": [ { "model": "itunes", "scope": "lt", "trust": 1.0, "vendor": "apple", "version": "12.7.4" }, { "model": "icloud", "scope": "lt", "trust": 1.0, "vendor": "apple", "version": "7.4" }, { "model": "enterprise linux workstation", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "6.0" }, { "model": "ubuntu linux", "scope": "eq", "trust": 1.0, "vendor": "canonical", "version": "16.04" }, { "model": "iphone os", "scope": "lt", "trust": 1.0, "vendor": "apple", "version": "11.3" }, { "model": "safari", "scope": "lt", "trust": 1.0, "vendor": "apple", "version": "11.1" }, { "model": "watchos", "scope": "lt", "trust": 1.0, "vendor": "apple", "version": "4.3" }, { "model": "webkitgtk\\+", "scope": "lt", "trust": 1.0, "vendor": "webkitgtk", "version": "2.20.4" }, { "model": "enterprise linux server", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "6.0" }, { "model": "linux", "scope": "eq", "trust": 1.0, "vendor": "debian", "version": "9.0" }, { "model": "enterprise linux desktop", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "6.0" }, { "model": "ubuntu linux", "scope": "eq", "trust": 1.0, "vendor": "canonical", "version": "17.10" }, { "model": "icloud", "scope": "lt", "trust": 0.8, "vendor": "apple", "version": "7.4 (windows 7 or later )" }, { "model": "ios", "scope": "lt", "trust": 0.8, "vendor": "apple", "version": "11.3 (ipad air or later )" }, { "model": "ios", "scope": "lt", "trust": 0.8, "vendor": "apple", "version": "11.3 (iphone 5s or later )" }, { "model": "ios", "scope": "lt", "trust": 0.8, "vendor": "apple", "version": "11.3 (ipod touch first 6 generation )" }, { "model": "itunes", "scope": "lt", "trust": 0.8, "vendor": "apple", "version": "for windows 12.7.4 (windows 7 or later )" }, { "model": "safari", "scope": "lt", "trust": 0.8, "vendor": "apple", "version": "11.1 (macos high sierra 10.13.4)" }, { "model": "safari", "scope": "lt", "trust": 0.8, "vendor": "apple", "version": "11.1 (macos sierra 10.12.6)" }, { "model": "safari", "scope": "lt", "trust": 0.8, "vendor": "apple", "version": "11.1 (os x el capitan 10.11.6)" }, { "model": "watchos", "scope": "lt", "trust": 0.8, "vendor": "apple", "version": "4.3 (apple watch all models )" }, { "model": "safari", "scope": "eq", "trust": 0.6, "vendor": "apple", "version": "1.0.0b2" }, { "model": "safari", "scope": "eq", "trust": 0.6, "vendor": "apple", "version": null }, { "model": "safari", "scope": "eq", "trust": 0.6, "vendor": "apple", "version": "1.0.0" }, { "model": "safari", "scope": "eq", "trust": 0.6, "vendor": "apple", "version": "1.0.3" }, { "model": "safari", "scope": "eq", "trust": 0.6, "vendor": "apple", "version": "1.0" }, { "model": "safari", "scope": "eq", "trust": 0.6, "vendor": "apple", "version": "1.0.1" }, { "model": "safari", "scope": "eq", "trust": 0.6, "vendor": "apple", "version": "1.0.0b1" }, { "model": "safari", "scope": "eq", "trust": 0.6, "vendor": "apple", "version": "1.0.2" } ], "sources": [ { "db": "JVNDB", "id": "JVNDB-2018-003665" }, { "db": "CNNVD", "id": "CNNVD-201804-188" }, { "db": "NVD", "id": "CVE-2018-4117" } ] }, "configurations": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/configurations#", "children": { "@container": "@list" }, "cpe_match": { "@container": "@list" }, "data": { "@container": "@list" }, "nodes": { "@container": "@list" } }, "data": [ { "CVE_data_version": "4.0", "nodes": [ { "cpe_match": [ { "cpe22Uri": "cpe:/a:apple:icloud", "vulnerable": true }, { "cpe22Uri": "cpe:/o:apple:iphone_os", "vulnerable": true }, { "cpe22Uri": "cpe:/a:apple:itunes", "vulnerable": true }, { "cpe22Uri": "cpe:/a:apple:safari", "vulnerable": true }, { "cpe22Uri": "cpe:/o:apple:watchos", "vulnerable": true } ], "operator": "OR" } ] } ], "sources": [ { "db": "JVNDB", "id": "JVNDB-2018-003665" } ] }, "credits": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/credits#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": "Apple", "sources": [ { "db": "PACKETSTORM", "id": "146965" }, { "db": "PACKETSTORM", "id": "146970" }, { "db": "PACKETSTORM", "id": "146971" } ], "trust": 0.3 }, "cve": "CVE-2018-4117", "cvss": { "@context": { "cvssV2": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/cvss/cvssV2#" }, "@id": "https://www.variotdbs.pl/ref/cvss/cvssV2" }, "cvssV3": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/cvss/cvssV3#" }, "@id": "https://www.variotdbs.pl/ref/cvss/cvssV3/" }, "severity": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/cvss/severity#" }, "@id": "https://www.variotdbs.pl/ref/cvss/severity" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" }, "@id": "https://www.variotdbs.pl/ref/sources" } }, "data": [ { "cvssV2": [ { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "author": "nvd@nist.gov", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "PARTIAL", "exploitabilityScore": 8.6, "id": "CVE-2018-4117", "impactScore": 2.9, "integrityImpact": "NONE", "severity": "MEDIUM", "trust": 1.9, "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "version": "2.0" }, { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "author": "VULHUB", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "PARTIAL", "exploitabilityScore": 8.6, "id": "VHN-134148", "impactScore": 2.9, "integrityImpact": "NONE", "severity": "MEDIUM", "trust": 0.1, "vectorString": "AV:N/AC:M/AU:N/C:P/I:N/A:N", "version": "2.0" } ], "cvssV3": [ { "attackComplexity": "LOW", "attackVector": "NETWORK", "author": "nvd@nist.gov", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "exploitabilityScore": 2.8, "id": "CVE-2018-4117", "impactScore": 3.6, "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "trust": 1.8, "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" } ], "severity": [ { "author": "nvd@nist.gov", "id": "CVE-2018-4117", "trust": 1.0, "value": "MEDIUM" }, { "author": "NVD", "id": "CVE-2018-4117", "trust": 0.8, "value": "Medium" }, { "author": "CNNVD", "id": "CNNVD-201804-188", "trust": 0.6, "value": "MEDIUM" }, { "author": "VULHUB", "id": "VHN-134148", "trust": 0.1, "value": "MEDIUM" }, { "author": "VULMON", "id": "CVE-2018-4117", "trust": 0.1, "value": "MEDIUM" } ] } ], "sources": [ { "db": "VULHUB", "id": "VHN-134148" }, { "db": "VULMON", "id": "CVE-2018-4117" }, { "db": "JVNDB", "id": "JVNDB-2018-003665" }, { "db": "CNNVD", "id": "CNNVD-201804-188" }, { "db": "NVD", "id": "CVE-2018-4117" } ] }, "description": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/description#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": "An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the \"WebKit\" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. Apple iOS, iCloud for Windows, iTunes for Windows, Safari, and tvOS are all products of the American company Apple (Apple). Apple iOS is an operating system developed for mobile devices; Safari is a web browser that comes with the Mac OS X and iOS operating systems by default. WebKit is an open source web browser engine developed by the KDE community and is currently used by browsers such as Apple Safari and Google Chrome. ------------------------------------------------------------------------\nWebKitGTK+ Security Advisory WSA-2018-0003\n------------------------------------------------------------------------\n\nDate reported : April 04, 2018\nAdvisory ID : WSA-2018-0003\nAdvisory URL : https://webkitgtk.org/security/WSA-2018-0003.html\nCVE identifiers : CVE-2018-4101, CVE-2018-4113, CVE-2018-4114,\n CVE-2018-4117, CVE-2018-4118, CVE-2018-4119,\n CVE-2018-4120, CVE-2018-4122, CVE-2018-4125,\n CVE-2018-4127, CVE-2018-4128, CVE-2018-4129,\n CVE-2018-4133, CVE-2018-4146, CVE-2018-4161,\n CVE-2018-4162, CVE-2018-4163, CVE-2018-4165. \n\nSeveral vulnerabilities were discovered in WebKitGTK+. \n Credit to Yuan Deng of Ant-financial Light-Year Security Lab. \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n Credit to OSS-Fuzz. \n Impact: Unexpected interaction with indexing types causing an ASSERT\n failure. Description: An array indexing issue existed in the\n handling of a function in JavaScriptCore. This issue was addressed\n through improved checks. \n Credit to OSS-Fuzz. \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n Credit to an anonymous researcher. \n Impact: A malicious website may exfiltrate data cross-origin. This\n was addressed through improved input validation. \n Credit to Jun Kokatsu (@shhnjk). \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n Credit to an anonymous researcher working with Trend Microys Zero\n Day Initiative. \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n Credit to Hanming Zhang (@4shitak4) of Qihoo 360 Vulcan Team. \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n Credit to WanderingGlitch of Trend Micro\u0027s Zero Day Initiative. \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n Credit to WanderingGlitch of Trend Micro\u0027s Zero Day Initiative. \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n Credit to an anonymous researcher working with Trend Microys Zero\n Day Initiative. \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n Credit to Zach Markley. \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n Credit to likemeng of Baidu Security Lab working with Trend Micro\u0027s\n Zero Day Initiative. \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n Credit to Anton Lopanitsyn of Wallarm, Linus Sarud of Detectify\n (detectify.com), Yuji Tounai of NTT Communications Corporation. \n Impact: Visiting a maliciously crafted website may lead to a cross-\n site scripting attack. Description: A cross-site scripting issue\n existed in WebKit. This issue was addressed with improved URL\n validation. \n Credit to OSS-Fuzz. \n Impact: Processing maliciously crafted web content may lead to a\n denial of service. Description: A memory corruption issue was\n addressed through improved input validation. \n Credit to WanderingGlitch of Trend Micro\u0027s Zero Day Initiative. \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n Credit to WanderingGlitch of Trend Micro\u0027s Zero Day Initiative. \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n Credit to WanderingGlitch of Trend Micro\u0027s Zero Day Initiative. \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n Credit to Hanming Zhang (@4shitak4) of Qihoo 360 Vulcan Team. \n Impact: Processing maliciously crafted web content may lead to\n arbitrary code execution. Description: Multiple memory corruption\n issues were addressed with improved memory handling. \n\n\nWe recommend updating to the last stable version of WebKitGTK+. It is\nthe best way of ensuring that you are running a safe version of\nWebKitGTK+. Please check our website for information about the last\nstable releases. \n\nFurther information about WebKitGTK+ Security Advisories can be found\nat: https://webkitgtk.org/security.html\n\nThe WebKitGTK+ team,\nApril 04, 2018\n. -----BEGIN PGP SIGNED MESSAGE-----\nHash: SHA512\n\nAPPLE-SA-2018-3-29-2 watchOS 4.3\n\nwatchOS 4.3 is now available and addresses the following:\n\nCoreFoundation\nAvailable for: All Apple Watch models\nImpact: An application may be able to gain elevated privileges\nDescription: A race condition was addressed with additional\nvalidation. \nCVE-2018-4142: Robin Leroy of Google Switzerland GmbH\n\nFile System Events\nAvailable for: All Apple Watch models\nImpact: An application may be able to gain elevated privileges\nDescription: A race condition was addressed with additional\nvalidation. \nCVE-2018-4104: The UK\u0027s National Cyber Security Centre (NCSC)\n\nKernel\nAvailable for: All Apple Watch models\nImpact: An application may be able to execute arbitrary code with\nkernel privileges\nDescription: A memory corruption issue was addressed with improved\nmemory handling. \nCVE-2018-4143: derrek (@derrekr6)\n\nNSURLSession\nAvailable for: All Apple Watch models\nImpact: An application may be able to gain elevated privileges\nDescription: A race condition was addressed with additional\nvalidation. \nCVE-2018-4166: Samuel GroA (@5aelo)\n\nQuick Look\nAvailable for: All Apple Watch models\nImpact: An application may be able to gain elevated privileges\nDescription: A race condition was addressed with additional\nvalidation. \nCVE-2018-4157: Samuel GroA (@5aelo)\n\nSecurity\nAvailable for: All Apple Watch models\nImpact: A malicious application may be able to elevate privileges\nDescription: A buffer overflow was addressed with improved size\nvalidation. \nCVE-2018-4144: Abraham Masri (@cheesecakeufo)\n\nSystem Preferences\nAvailable for: All Apple Watch models\nImpact: A configuration profile may incorrectly remain in effect\nafter removal\nDescription: An issue existed in CFPreferences. \nCVE-2018-4117: an anonymous researcher, an anonymous researcher\n\nInstallation note:\n\nInstructions on how to update your Apple Watch software are\navailable at https://support.apple.com/kb/HT204641\n\nTo check the version on your Apple Watch, open the Apple Watch app\non your iPhone and select \"My Watch \u003e General \u003e About\". \n\nAlternatively, on your watch, select \"My Watch \u003e General \u003e About\". ==========================================================================\nUbuntu Security Notice USN-3635-1\nApril 30, 2018\n\nwebkit2gtk vulnerabilities\n==========================================================================\n\nA security issue affects these releases of Ubuntu and its derivatives:\n\n- Ubuntu 17.10\n- Ubuntu 16.04 LTS\n\nSummary:\n\nSeveral security issues were fixed in WebKitGTK+. \n\nSoftware Description:\n- webkit2gtk: Web content engine library for GTK+\n\nDetails:\n\nA large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution. \n\nUpdate instructions:\n\nThe problem can be corrected by updating your system to the following\npackage versions:\n\nUbuntu 17.10:\n libjavascriptcoregtk-4.0-18 2.20.1-0ubuntu0.17.10.1\n libwebkit2gtk-4.0-37 2.20.1-0ubuntu0.17.10.1\n\nUbuntu 16.04 LTS:\n libjavascriptcoregtk-4.0-18 2.20.1-0ubuntu0.16.04.1\n libwebkit2gtk-4.0-37 2.20.1-0ubuntu0.16.04.1\n\nThis update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes. -----BEGIN PGP SIGNED MESSAGE-----\nHash: SHA256\n\n==================================================================== \nRed Hat Security Advisory\n\nSynopsis: Important: chromium-browser security update\nAdvisory ID: RHSA-2018:2282-01\nProduct: Red Hat Enterprise Linux Supplementary\nAdvisory URL: https://access.redhat.com/errata/RHSA-2018:2282\nIssue date: 2018-07-30\nCVE Names: CVE-2018-4117 CVE-2018-6044 CVE-2018-6150\n CVE-2018-6151 CVE-2018-6152 CVE-2018-6153\n CVE-2018-6154 CVE-2018-6155 CVE-2018-6156\n CVE-2018-6157 CVE-2018-6158 CVE-2018-6159\n CVE-2018-6161 CVE-2018-6162 CVE-2018-6163\n CVE-2018-6164 CVE-2018-6165 CVE-2018-6166\n CVE-2018-6167 CVE-2018-6168 CVE-2018-6169\n CVE-2018-6170 CVE-2018-6171 CVE-2018-6172\n CVE-2018-6173 CVE-2018-6174 CVE-2018-6175\n CVE-2018-6176 CVE-2018-6177 CVE-2018-6178\n CVE-2018-6179\n====================================================================\n1. Summary:\n\nAn update for chromium-browser is now available for Red Hat Enterprise\nLinux 6 Supplementary. \n\nRed Hat Product Security has rated this update as having a security impact\nof Important. A Common Vulnerability Scoring System (CVSS) base score,\nwhich gives a detailed severity rating, is available for each vulnerability\nfrom the CVE link(s) in the References section. \n\n2. Relevant releases/architectures:\n\nRed Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64\nRed Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64\nRed Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64\n\n3. Description:\n\nChromium is an open-source web browser, powered by WebKit (Blink). \n\nThis update upgrades Chromium to version 68.0.3440.75. \n\nSecurity Fix(es):\n\n* chromium-browser: Stack buffer overflow in Skia (CVE-2018-6153)\n\n* chromium-browser: Heap buffer overflow in WebGL (CVE-2018-6154)\n\n* chromium-browser: Use after free in WebRTC (CVE-2018-6155)\n\n* chromium-browser: Heap buffer overflow in WebRTC (CVE-2018-6156)\n\n* chromium-browser: Type confusion in WebRTC (CVE-2018-6157)\n\n* chromium-browser: Cross origin information disclosure in Service Workers\n(CVE-2018-6150)\n\n* chromium-browser: Bad cast in DevTools (CVE-2018-6151)\n\n* chromium-browser: Local file write in DevTools (CVE-2018-6152)\n\n* chromium-browser: Use after free in Blink (CVE-2018-6158)\n\n* chromium-browser: Same origin policy bypass in ServiceWorker\n(CVE-2018-6159)\n\n* chromium-browser: Same origin policy bypass in WebAudio (CVE-2018-6161)\n\n* chromium-browser: Heap buffer overflow in WebGL (CVE-2018-6162)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6163)\n\n* chromium-browser: Same origin policy bypass in ServiceWorker\n(CVE-2018-6164)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6165)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6166)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6167)\n\n* chromium-browser: CORS bypass in Blink (CVE-2018-6168)\n\n* chromium-browser: Permissions bypass in extension installation\n(CVE-2018-6169)\n\n* chromium-browser: Type confusion in PDFium (CVE-2018-6170)\n\n* chromium-browser: Use after free in WebBluetooth (CVE-2018-6171)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6172)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6173)\n\n* chromium-browser: Integer overflow in SwiftShader (CVE-2018-6174)\n\n* chromium-browser: URL spoof in Omnibox (CVE-2018-6175)\n\n* chromium-browser: Local user privilege escalation in Extensions\n(CVE-2018-6176)\n\n* chromium-browser: Cross origin information leak in Blink (CVE-2018-4117)\n\n* chromium-browser: Request privilege escalation in Extensions\n(CVE-2018-6044)\n\n* chromium-browser: Cross origin information leak in Blink (CVE-2018-6177)\n\n* chromium-browser: UI spoof in Extensions (CVE-2018-6178)\n\n* chromium-browser: Local file information leak in Extensions\n(CVE-2018-6179)\n\nFor more details about the security issue(s), including the impact, a CVSS\nscore, and other related information, refer to the CVE page(s) listed in\nthe References section. \n\n4. Solution:\n\nFor details on how to apply this update, which includes the changes\ndescribed in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the update, Chromium must be restarted for the changes to\ntake effect. \n\n5. Bugs fixed (https://bugzilla.redhat.com/):\n\n1608177 - CVE-2018-6153 chromium-browser: Stack buffer overflow in Skia\n1608178 - CVE-2018-6154 chromium-browser: Heap buffer overflow in WebGL\n1608179 - CVE-2018-6155 chromium-browser: Use after free in WebRTC\n1608180 - CVE-2018-6156 chromium-browser: Heap buffer overflow in WebRTC\n1608181 - CVE-2018-6157 chromium-browser: Type confusion in WebRTC\n1608182 - CVE-2018-6158 chromium-browser: Use after free in Blink\n1608183 - CVE-2018-6159 chromium-browser: Same origin policy bypass in ServiceWorker\n1608185 - CVE-2018-6161 chromium-browser: Same origin policy bypass in WebAudio\n1608186 - CVE-2018-6162 chromium-browser: Heap buffer overflow in WebGL\n1608187 - CVE-2018-6163 chromium-browser: URL spoof in Omnibox\n1608188 - CVE-2018-6164 chromium-browser: Same origin policy bypass in ServiceWorker\n1608189 - CVE-2018-6165 chromium-browser: URL spoof in Omnibox\n1608190 - CVE-2018-6166 chromium-browser: URL spoof in Omnibox\n1608191 - CVE-2018-6167 chromium-browser: URL spoof in Omnibox\n1608192 - CVE-2018-6168 chromium-browser: CORS bypass in Blink\n1608193 - CVE-2018-6169 chromium-browser: Permissions bypass in extension installation\n1608194 - CVE-2018-6170 chromium-browser: Type confusion in PDFium\n1608195 - CVE-2018-6171 chromium-browser: Use after free in WebBluetooth\n1608196 - CVE-2018-6172 chromium-browser: URL spoof in Omnibox\n1608197 - CVE-2018-6173 chromium-browser: URL spoof in Omnibox\n1608198 - CVE-2018-6174 chromium-browser: Integer overflow in SwiftShader\n1608199 - CVE-2018-6175 chromium-browser: URL spoof in Omnibox\n1608200 - CVE-2018-6176 chromium-browser: Local user privilege escalation in Extensions\n1608201 - CVE-2018-6177 chromium-browser: Cross origin information leak in Blink\n1608202 - CVE-2018-6178 chromium-browser: UI spoof in Extensions\n1608203 - CVE-2018-6179 chromium-browser: Local file information leak in Extensions\n1608204 - CVE-2018-6044 chromium-browser: Request privilege escalation in Extensions\n1608205 - CVE-2018-4117 chromium-browser: Cross origin information leak in Blink\n1608206 - CVE-2018-6150 chromium-browser: Cross origin information disclosure in Service Workers\n1608207 - CVE-2018-6151 chromium-browser: Bad cast in DevTools\n1608208 - CVE-2018-6152 chromium-browser: Local file write in DevTools\n\n6. Package List:\n\nRed Hat Enterprise Linux Desktop Supplementary (v. 6):\n\ni386:\nchromium-browser-68.0.3440.75-1.el6_10.i686.rpm\nchromium-browser-debuginfo-68.0.3440.75-1.el6_10.i686.rpm\n\nx86_64:\nchromium-browser-68.0.3440.75-1.el6_10.x86_64.rpm\nchromium-browser-debuginfo-68.0.3440.75-1.el6_10.x86_64.rpm\n\nRed Hat Enterprise Linux Server Supplementary (v. 6):\n\ni386:\nchromium-browser-68.0.3440.75-1.el6_10.i686.rpm\nchromium-browser-debuginfo-68.0.3440.75-1.el6_10.i686.rpm\n\nx86_64:\nchromium-browser-68.0.3440.75-1.el6_10.x86_64.rpm\nchromium-browser-debuginfo-68.0.3440.75-1.el6_10.x86_64.rpm\n\nRed Hat Enterprise Linux Workstation Supplementary (v. 6):\n\ni386:\nchromium-browser-68.0.3440.75-1.el6_10.i686.rpm\nchromium-browser-debuginfo-68.0.3440.75-1.el6_10.i686.rpm\n\nx86_64:\nchromium-browser-68.0.3440.75-1.el6_10.x86_64.rpm\nchromium-browser-debuginfo-68.0.3440.75-1.el6_10.x86_64.rpm\n\nThese packages are GPG signed by Red Hat for security. Our key and\ndetails on how to verify the signature are available from\nhttps://access.redhat.com/security/team/key/\n\n7. References:\n\nhttps://access.redhat.com/security/cve/CVE-2018-4117\nhttps://access.redhat.com/security/cve/CVE-2018-6044\nhttps://access.redhat.com/security/cve/CVE-2018-6150\nhttps://access.redhat.com/security/cve/CVE-2018-6151\nhttps://access.redhat.com/security/cve/CVE-2018-6152\nhttps://access.redhat.com/security/cve/CVE-2018-6153\nhttps://access.redhat.com/security/cve/CVE-2018-6154\nhttps://access.redhat.com/security/cve/CVE-2018-6155\nhttps://access.redhat.com/security/cve/CVE-2018-6156\nhttps://access.redhat.com/security/cve/CVE-2018-6157\nhttps://access.redhat.com/security/cve/CVE-2018-6158\nhttps://access.redhat.com/security/cve/CVE-2018-6159\nhttps://access.redhat.com/security/cve/CVE-2018-6161\nhttps://access.redhat.com/security/cve/CVE-2018-6162\nhttps://access.redhat.com/security/cve/CVE-2018-6163\nhttps://access.redhat.com/security/cve/CVE-2018-6164\nhttps://access.redhat.com/security/cve/CVE-2018-6165\nhttps://access.redhat.com/security/cve/CVE-2018-6166\nhttps://access.redhat.com/security/cve/CVE-2018-6167\nhttps://access.redhat.com/security/cve/CVE-2018-6168\nhttps://access.redhat.com/security/cve/CVE-2018-6169\nhttps://access.redhat.com/security/cve/CVE-2018-6170\nhttps://access.redhat.com/security/cve/CVE-2018-6171\nhttps://access.redhat.com/security/cve/CVE-2018-6172\nhttps://access.redhat.com/security/cve/CVE-2018-6173\nhttps://access.redhat.com/security/cve/CVE-2018-6174\nhttps://access.redhat.com/security/cve/CVE-2018-6175\nhttps://access.redhat.com/security/cve/CVE-2018-6176\nhttps://access.redhat.com/security/cve/CVE-2018-6177\nhttps://access.redhat.com/security/cve/CVE-2018-6178\nhttps://access.redhat.com/security/cve/CVE-2018-6179\nhttps://access.redhat.com/security/updates/classification/#important\n\n8. Contact:\n\nThe Red Hat security contact is \u003csecalert@redhat.com\u003e. More contact\ndetails at https://access.redhat.com/security/team/contact/\n\nCopyright 2018 Red Hat, Inc. \n-----BEGIN PGP SIGNATURE-----\nVersion: GnuPG v1\n\niQIVAwUBW18qZtzjgjWX9erEAQhZ2w/+O2aOCGCk2DIKqwT/ErfmvasFiNz7u8I1\n+yPMYTQ1NFrs8cjt/ym7PH50aFOMS/YO3n/YL5ROLzoDW/PqXvJdxvi9opWG958V\nftc20yBBa4EdJExqkKQYefxg9qD4emt6jkVBzSd/xZ3XcF50oKBG0m1aEPmCzM/G\n+o3ohQPiKgAMXJMtqTvSXxy1dV0LuoFOWYS6FPrO2F2MzY0Vd8/GXP1bnxqqqYxT\nohA0f2yoPWVGzQQBRGCeHvTjv6Mt0PdGejKAoUxptgXenOQ9xAyRBuhSBkvBXAAN\n3m+pEmWpHdOdEWoiIx07QcaH408ji+gs2oMSybS16PUwe9VsuOOJBOgFSLjxdb3d\nbzUjIKZHHscjxA1KIVtAx2JdqTLUKlSjSvaaZxa5d/wFq2UticBM8+EotuIOdE5J\n6BVLVX+0GUCizPNbgC2f4i2G3xd60uiym9KP70Z7X+W7vMl9qXcab+GOJCAufwY8\n+dfchywwsT19FdQLBJEjKPm7b33FNdr0oLvg6D5RK4pdJMYiEXoCt6ElLBBQzSEA\n3vXsagWAaeDEBsLeDNapkLh1BHUx86iMVLGUtiwFgbtAXg7Jbz82AHZmtwT1bf6I\nKR7aOFFs2zKjRSuQDQZlOPNQVCt04+NbMZYEw6cHIT/+wX7ZrXaNZp+4tTo9gnOf\nR1+VLpZrH1Q=jHL1\n-----END PGP SIGNATURE-----\n\n--\nRHSA-announce mailing list\nRHSA-announce@redhat.com\nhttps://www.redhat.com/mailman/listinfo/rhsa-announce\n. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\nGentoo Linux Security Advisory GLSA 201808-01\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\n https://security.gentoo.org/\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\n\n Severity: Normal\n Title: Chromium, Google Chrome: Multiple vulnerabilities\n Date: August 22, 2018\n Bugs: #657376, #662436\n ID: 201808-01\n\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\n\nSynopsis\n========\n\nMultiple vulnerabilities have been found in Chromium and Google Chrome,\nthe worst of which allows remote attackers to escalate privileges. \n\nBackground\n==========\n\nChromium is an open-source browser project that aims to build a safer,\nfaster, and more stable way for all users to experience the web. \n\nGoogle Chrome is one fast, simple, and secure browser for all your\ndevices. \n\nAffected packages\n=================\n\n -------------------------------------------------------------------\n Package / Vulnerable / Unaffected\n -------------------------------------------------------------------\n 1 www-client/chromium \u003c 68.0.3440.75 \u003e= 68.0.3440.75\n 2 www-client/google-chrome\n \u003c 68.0.3440.75 \u003e= 68.0.3440.75\n -------------------------------------------------------------------\n 2 affected packages\n\nDescription\n===========\n\nMultiple vulnerabilities have been discovered in Chromium and Google\nChrome. Please review the referenced CVE identifiers and Google Chrome\nReleases for details. \n\nWorkaround\n==========\n\nThere is no known workaround at this time. \n\nResolution\n==========\n\nAll Chromium users should upgrade to the latest version:\n\n # emerge --sync\n # emerge --ask --oneshot -v \"\u003e=www-client/chromium-68.0.3440.75\"\n\nAll Google Chrome users should upgrade to the latest version:\n\n # emerge --sync\n # emerge --ask --oneshot -v \"\u003e=www-client/google-chrome-68.0.3440.75\"\n\nReferences\n==========\n\n[ 1 ] CVE-2018-4117\n https://nvd.nist.gov/vuln/detail/CVE-2018-4117\n[ 2 ] CVE-2018-6044\n https://nvd.nist.gov/vuln/detail/CVE-2018-6044\n[ 3 ] CVE-2018-6150\n https://nvd.nist.gov/vuln/detail/CVE-2018-6150\n[ 4 ] CVE-2018-6151\n https://nvd.nist.gov/vuln/detail/CVE-2018-6151\n[ 5 ] CVE-2018-6152\n https://nvd.nist.gov/vuln/detail/CVE-2018-6152\n[ 6 ] CVE-2018-6153\n https://nvd.nist.gov/vuln/detail/CVE-2018-6153\n[ 7 ] CVE-2018-6154\n https://nvd.nist.gov/vuln/detail/CVE-2018-6154\n[ 8 ] CVE-2018-6155\n https://nvd.nist.gov/vuln/detail/CVE-2018-6155\n[ 9 ] CVE-2018-6156\n https://nvd.nist.gov/vuln/detail/CVE-2018-6156\n[ 10 ] CVE-2018-6157\n https://nvd.nist.gov/vuln/detail/CVE-2018-6157\n[ 11 ] CVE-2018-6158\n https://nvd.nist.gov/vuln/detail/CVE-2018-6158\n[ 12 ] CVE-2018-6159\n https://nvd.nist.gov/vuln/detail/CVE-2018-6159\n[ 13 ] CVE-2018-6160\n https://nvd.nist.gov/vuln/detail/CVE-2018-6160\n[ 14 ] CVE-2018-6161\n https://nvd.nist.gov/vuln/detail/CVE-2018-6161\n[ 15 ] CVE-2018-6162\n https://nvd.nist.gov/vuln/detail/CVE-2018-6162\n[ 16 ] CVE-2018-6163\n https://nvd.nist.gov/vuln/detail/CVE-2018-6163\n[ 17 ] CVE-2018-6164\n https://nvd.nist.gov/vuln/detail/CVE-2018-6164\n[ 18 ] CVE-2018-6165\n https://nvd.nist.gov/vuln/detail/CVE-2018-6165\n[ 19 ] CVE-2018-6166\n https://nvd.nist.gov/vuln/detail/CVE-2018-6166\n[ 20 ] CVE-2018-6167\n https://nvd.nist.gov/vuln/detail/CVE-2018-6167\n[ 21 ] CVE-2018-6168\n https://nvd.nist.gov/vuln/detail/CVE-2018-6168\n[ 22 ] CVE-2018-6169\n https://nvd.nist.gov/vuln/detail/CVE-2018-6169\n[ 23 ] CVE-2018-6170\n https://nvd.nist.gov/vuln/detail/CVE-2018-6170\n[ 24 ] CVE-2018-6171\n https://nvd.nist.gov/vuln/detail/CVE-2018-6171\n[ 25 ] CVE-2018-6172\n https://nvd.nist.gov/vuln/detail/CVE-2018-6172\n[ 26 ] CVE-2018-6173\n https://nvd.nist.gov/vuln/detail/CVE-2018-6173\n[ 27 ] CVE-2018-6174\n https://nvd.nist.gov/vuln/detail/CVE-2018-6174\n[ 28 ] CVE-2018-6175\n https://nvd.nist.gov/vuln/detail/CVE-2018-6175\n[ 29 ] CVE-2018-6176\n https://nvd.nist.gov/vuln/detail/CVE-2018-6176\n[ 30 ] CVE-2018-6177\n https://nvd.nist.gov/vuln/detail/CVE-2018-6177\n[ 31 ] CVE-2018-6178\n https://nvd.nist.gov/vuln/detail/CVE-2018-6178\n[ 32 ] CVE-2018-6179\n https://nvd.nist.gov/vuln/detail/CVE-2018-6179\n[ 33 ] CVE-2108-6150\n https://nvd.nist.gov/vuln/detail/CVE-2108-6150\n[ 34 ] Google Chrome 68.0.3440.75 release announcement\n\nhttps://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html\n\nAvailability\n============\n\nThis GLSA and any updates to it are available for viewing at\nthe Gentoo Security Website:\n\n https://security.gentoo.org/glsa/201808-01\n\nConcerns?\n=========\n\nSecurity is a primary focus of Gentoo Linux and ensuring the\nconfidentiality and security of our users\u0027 machines is of utmost\nimportance to us. Any security concerns should be addressed to\nsecurity@gentoo.org or alternatively, you may file a bug at\nhttps://bugs.gentoo.org. \n\nLicense\n=======\n\nCopyright 2018 Gentoo Foundation, Inc; referenced text\nbelongs to its owner(s). \n\nThe contents of this document are licensed under the\nCreative Commons - Attribution / Share Alike license. \n\nhttps://creativecommons.org/licenses/by-sa/2.5\n\n", "sources": [ { "db": "NVD", "id": "CVE-2018-4117" }, { "db": "JVNDB", "id": "JVNDB-2018-003665" }, { "db": "VULHUB", "id": "VHN-134148" }, { "db": "VULMON", "id": "CVE-2018-4117" }, { "db": "PACKETSTORM", "id": "147241" }, { "db": "PACKETSTORM", "id": "146965" }, { "db": "PACKETSTORM", "id": "147433" }, { "db": "PACKETSTORM", "id": "148738" }, { "db": "PACKETSTORM", "id": "146970" }, { "db": "PACKETSTORM", "id": "149044" }, { "db": "PACKETSTORM", "id": "146971" } ], "trust": 2.43 }, "external_ids": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/external_ids#", "data": { "@container": "@list" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": [ { "db": "NVD", "id": "CVE-2018-4117", "trust": 3.3 }, { "db": "SECTRACK", "id": "1040604", "trust": 1.2 }, { "db": "BID", "id": "104887", "trust": 1.2 }, { "db": "JVN", "id": "JVNVU92378299", "trust": 0.8 }, { "db": "JVNDB", "id": "JVNDB-2018-003665", "trust": 0.8 }, { "db": "CNNVD", "id": "CNNVD-201804-188", "trust": 0.7 }, { "db": "PACKETSTORM", "id": "148738", "trust": 0.2 }, { "db": "PACKETSTORM", "id": "149044", "trust": 0.2 }, { "db": "PACKETSTORM", "id": "148722", "trust": 0.1 }, { "db": "VULHUB", "id": "VHN-134148", "trust": 0.1 }, { "db": "VULMON", "id": "CVE-2018-4117", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "147241", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "146965", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "147433", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "146970", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "146971", "trust": 0.1 } ], "sources": [ { "db": "VULHUB", "id": "VHN-134148" }, { "db": "VULMON", "id": "CVE-2018-4117" }, { "db": "JVNDB", "id": "JVNDB-2018-003665" }, { "db": "PACKETSTORM", "id": "147241" }, { "db": "PACKETSTORM", "id": "146965" }, { "db": "PACKETSTORM", "id": "147433" }, { "db": "PACKETSTORM", "id": "148738" }, { "db": "PACKETSTORM", "id": "146970" }, { "db": "PACKETSTORM", "id": "149044" }, { "db": "PACKETSTORM", "id": "146971" }, { "db": "CNNVD", "id": "CNNVD-201804-188" }, { "db": "NVD", "id": "CVE-2018-4117" } ] }, "id": "VAR-201804-1177", "iot": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/iot#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": true, "sources": [ { "db": "VULHUB", "id": "VHN-134148" } ], "trust": 0.01 }, "last_update_date": "2024-09-19T22:31:42.073000Z", "patch": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/patch#", "data": { "@container": "@list" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": [ { "title": "HT208697", "trust": 0.8, "url": "https://support.apple.com/en-us/HT208697" }, { "title": "HT208693", "trust": 0.8, "url": "https://support.apple.com/en-us/HT208693" }, { "title": "HT208694", "trust": 0.8, "url": "https://support.apple.com/en-us/HT208694" }, { "title": "HT208695", "trust": 0.8, "url": "https://support.apple.com/en-us/HT208695" }, { "title": "HT208696", "trust": 0.8, "url": "https://support.apple.com/en-us/HT208696" }, { "title": "HT208693", "trust": 0.8, "url": "https://support.apple.com/ja-jp/HT208693" }, { "title": "HT208694", "trust": 0.8, "url": "https://support.apple.com/ja-jp/HT208694" }, { "title": "HT208695", "trust": 0.8, "url": "https://support.apple.com/ja-jp/HT208695" }, { "title": "HT208696", "trust": 0.8, "url": "https://support.apple.com/ja-jp/HT208696" }, { "title": "HT208697", "trust": 0.8, "url": "https://support.apple.com/ja-jp/HT208697" }, { "title": "Multiple Apple product WebKit Security vulnerabilities", "trust": 0.6, "url": "http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=83040" }, { "title": "Red Hat: CVE-2018-4117", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=red_hat_cve_database\u0026qid=CVE-2018-4117" }, { "title": "Red Hat: Important: chromium-browser security update", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories\u0026qid=RHSA-20182282 - Security Advisory" }, { "title": "Apple: Safari 11.1", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=apple_security_advisories\u0026qid=ee3f60ca20e25abaeeaa2929b7de559a" }, { "title": "Apple: watchOS 4.3", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=apple_security_advisories\u0026qid=0c9672f464c8ecdde98d280637ecb1c5" }, { "title": "Apple: iCloud for Windows 7.4", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=apple_security_advisories\u0026qid=3c324dcae1b032626ce2245c5900fb36" }, { "title": "Ubuntu Security Notice: webkit2gtk vulnerabilities", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice\u0026qid=USN-3635-1" }, { "title": "Apple: iTunes 12.7.4 for Windows", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=apple_security_advisories\u0026qid=1b3706ef4ba6948ac20ebbbcffe7bc29" }, { "title": "Oracle Solaris Third Party Bulletins: Oracle Solaris Third Party Bulletin - October 2018", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=oracle_solaris_third_party_bulletins\u0026qid=2196fa008592287290cbd6678fbe10d4" }, { "title": "Apple: iOS 11.3", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=apple_security_advisories\u0026qid=66db9acd354635a683838e3cd9bc2d76" }, { "title": "Debian Security Advisories: DSA-4256-1 chromium-browser -- security update", "trust": 0.1, "url": "https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories\u0026qid=1de398c860a3d18d1131a0f7f22cabdc" } ], "sources": [ { "db": "VULMON", "id": "CVE-2018-4117" }, { "db": "JVNDB", "id": "JVNDB-2018-003665" }, { "db": "CNNVD", "id": "CNNVD-201804-188" } ] }, "problemtype_data": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/problemtype_data#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": [ { "problemtype": "CWE-200", "trust": 1.9 } ], "sources": [ { "db": "VULHUB", "id": "VHN-134148" }, { "db": "JVNDB", "id": "JVNDB-2018-003665" }, { "db": "NVD", "id": "CVE-2018-4117" } ] }, "references": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/references#", "data": { "@container": "@list" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": [ { "trust": 1.8, "url": "https://support.apple.com/ht208693" }, { "trust": 1.8, "url": "https://support.apple.com/ht208694" }, { "trust": 1.8, "url": "https://support.apple.com/ht208695" }, { "trust": 1.8, "url": "https://support.apple.com/ht208696" }, { "trust": 1.8, "url": "https://support.apple.com/ht208697" }, { "trust": 1.5, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4117" }, { "trust": 1.3, "url": "https://security.gentoo.org/glsa/201808-01" }, { "trust": 1.3, "url": "https://access.redhat.com/errata/rhsa-2018:2282" }, { "trust": 1.3, "url": "https://usn.ubuntu.com/3635-1/" }, { "trust": 1.2, "url": "http://www.securityfocus.com/bid/104887" }, { "trust": 1.2, "url": "https://www.debian.org/security/2018/dsa-4256" }, { "trust": 1.2, "url": "https://security.gentoo.org/glsa/201808-04" }, { "trust": 1.2, "url": "http://www.securitytracker.com/id/1040604" }, { "trust": 0.8, "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-4117" }, { "trust": 0.8, "url": "http://jvn.jp/vu/jvnvu92378299/index.html" }, { "trust": 0.5, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4114" }, { "trust": 0.5, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4161" }, { "trust": 0.5, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4162" }, { "trust": 0.5, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4125" }, { "trust": 0.5, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4113" }, { "trust": 0.5, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4146" }, { "trust": 0.5, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4122" }, { "trust": 0.5, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4163" }, { "trust": 0.5, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4129" }, { "trust": 0.4, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4101" }, { "trust": 0.4, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4120" }, { "trust": 0.4, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4127" }, { "trust": 0.4, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4165" }, { "trust": 0.4, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4128" }, { "trust": 0.4, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4118" }, { "trust": 0.4, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4119" }, { "trust": 0.3, "url": "https://support.apple.com/kb/ht201222" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4144" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4121" }, { "trust": 0.3, "url": "https://www.apple.com/support/security/pgp/" }, { "trust": 0.2, "url": "https://access.redhat.com/security/cve/cve-2018-4117" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4133" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6154" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6171" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6167" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6169" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6163" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6166" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6170" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6161" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6155" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6162" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6175" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6176" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6174" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6156" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6164" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6168" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6159" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6172" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6157" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6044" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6158" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6173" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6152" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6151" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6165" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6153" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6150" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4130" }, { "trust": 0.1, "url": "https://cwe.mitre.org/data/definitions/200.html" }, { "trust": 0.1, "url": "https://nvd.nist.gov" }, { "trust": 0.1, "url": "https://webkitgtk.org/security/wsa-2018-0003.html" }, { "trust": 0.1, "url": "https://webkitgtk.org/security.html" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4155" }, { "trust": 0.1, "url": "https://support.apple.com/kb/ht204641" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4143" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4142" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4166" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4158" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4115" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4104" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4150" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4167" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-4157" }, { "trust": 0.1, "url": "https://usn.ubuntu.com/usn/usn-3635-1" }, { "trust": 0.1, "url": "https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.1-0ubuntu0.16.04.1" }, { "trust": 0.1, "url": "https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.1-0ubuntu0.17.10.1" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6157" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6168" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6152" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6155" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6164" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6151" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6161" }, { "trust": 0.1, "url": "https://access.redhat.com/security/updates/classification/#important" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6174" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6167" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6176" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6159" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6158" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6044" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6175" }, { "trust": 0.1, "url": "https://access.redhat.com/articles/11258" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6156" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6166" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6173" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6178" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6179" }, { "trust": 0.1, "url": "https://access.redhat.com/security/team/contact/" }, { "trust": 0.1, "url": "https://www.redhat.com/mailman/listinfo/rhsa-announce" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6154" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6163" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6171" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6153" }, { "trust": 0.1, "url": "https://bugzilla.redhat.com/):" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6172" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6165" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6177" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6170" }, { "trust": 0.1, "url": "https://access.redhat.com/security/team/key/" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6162" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6169" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-6150" }, { "trust": 0.1, "url": "https://www.apple.com/itunes/download/" }, { "trust": 0.1, "url": "https://bugs.gentoo.org." }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6178" }, { "trust": 0.1, "url": "https://security.gentoo.org/" }, { "trust": 0.1, "url": "https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6160" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6179" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-6177" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2108-6150" }, { "trust": 0.1, "url": "https://creativecommons.org/licenses/by-sa/2.5" }, { "trust": 0.1, "url": "https://support.apple.com/ht204283" } ], "sources": [ { "db": "VULHUB", "id": "VHN-134148" }, { "db": "VULMON", "id": "CVE-2018-4117" }, { "db": "JVNDB", "id": "JVNDB-2018-003665" }, { "db": "PACKETSTORM", "id": "147241" }, { "db": "PACKETSTORM", "id": "146965" }, { "db": "PACKETSTORM", "id": "147433" }, { "db": "PACKETSTORM", "id": "148738" }, { "db": "PACKETSTORM", "id": "146970" }, { "db": "PACKETSTORM", "id": "149044" }, { "db": "PACKETSTORM", "id": "146971" }, { "db": "CNNVD", "id": "CNNVD-201804-188" }, { "db": "NVD", "id": "CVE-2018-4117" } ] }, "sources": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#", "data": { "@container": "@list" } }, "data": [ { "db": "VULHUB", "id": "VHN-134148" }, { "db": "VULMON", "id": "CVE-2018-4117" }, { "db": "JVNDB", "id": "JVNDB-2018-003665" }, { "db": "PACKETSTORM", "id": "147241" }, { "db": "PACKETSTORM", "id": "146965" }, { "db": "PACKETSTORM", "id": "147433" }, { "db": "PACKETSTORM", "id": "148738" }, { "db": "PACKETSTORM", "id": "146970" }, { "db": "PACKETSTORM", "id": "149044" }, { "db": "PACKETSTORM", "id": "146971" }, { "db": "CNNVD", "id": "CNNVD-201804-188" }, { "db": "NVD", "id": "CVE-2018-4117" } ] }, "sources_release_date": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources_release_date#", "data": { "@container": "@list" } }, "data": [ { "date": "2018-04-03T00:00:00", "db": "VULHUB", "id": "VHN-134148" }, { "date": "2018-04-03T00:00:00", "db": "VULMON", "id": "CVE-2018-4117" }, { "date": "2018-06-01T00:00:00", "db": "JVNDB", "id": "JVNDB-2018-003665" }, { "date": "2018-04-18T13:33:33", "db": "PACKETSTORM", "id": "147241" }, { "date": "2018-03-30T15:52:32", "db": "PACKETSTORM", "id": "146965" }, { "date": "2018-05-02T04:32:41", "db": "PACKETSTORM", "id": "147433" }, { "date": "2018-07-30T17:19:05", "db": "PACKETSTORM", "id": "148738" }, { "date": "2018-03-30T15:55:41", "db": "PACKETSTORM", "id": "146970" }, { "date": "2018-08-22T23:01:00", "db": "PACKETSTORM", "id": "149044" }, { "date": "2018-03-30T15:56:03", "db": "PACKETSTORM", "id": "146971" }, { "date": "2018-04-03T00:00:00", "db": "CNNVD", "id": "CNNVD-201804-188" }, { "date": "2018-04-03T06:29:04.937000", "db": "NVD", "id": "CVE-2018-4117" } ] }, "sources_update_date": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources_update_date#", "data": { "@container": "@list" } }, "data": [ { "date": "2018-11-09T00:00:00", "db": "VULHUB", "id": "VHN-134148" }, { "date": "2018-11-09T00:00:00", "db": "VULMON", "id": "CVE-2018-4117" }, { "date": "2018-06-01T00:00:00", "db": "JVNDB", "id": "JVNDB-2018-003665" }, { "date": "2018-04-09T00:00:00", "db": "CNNVD", "id": "CNNVD-201804-188" }, { "date": "2018-11-09T17:58:22.260000", "db": "NVD", "id": "CVE-2018-4117" } ] }, "threat_type": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/threat_type#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": "remote", "sources": [ { "db": "PACKETSTORM", "id": "147433" }, { "db": "PACKETSTORM", "id": "149044" }, { "db": "CNNVD", "id": "CNNVD-201804-188" } ], "trust": 0.8 }, "title": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/title#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": "plural Apple Used in products WebKit Component fetch API Vulnerabilities that bypass the same origin policy", "sources": [ { "db": "JVNDB", "id": "JVNDB-2018-003665" } ], "trust": 0.8 }, "type": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/type#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": "information disclosure", "sources": [ { "db": "CNNVD", "id": "CNNVD-201804-188" } ], "trust": 0.6 } }
ghsa-m8xg-hqfh-frp5
Vulnerability from github
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
{ "affected": [], "aliases": [ "CVE-2018-4117" ], "database_specific": { "cwe_ids": [ "CWE-200" ], "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2018-04-03T06:29:00Z", "severity": "MODERATE" }, "details": "An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the \"WebKit\" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.", "id": "GHSA-m8xg-hqfh-frp5", "modified": "2022-05-14T02:00:27Z", "published": "2022-05-14T02:00:27Z", "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-4117" }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2018:2282" }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/201808-01" }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/201808-04" }, { "type": "WEB", "url": "https://support.apple.com/HT208693" }, { "type": "WEB", "url": "https://support.apple.com/HT208694" }, { "type": "WEB", "url": "https://support.apple.com/HT208695" }, { "type": "WEB", "url": "https://support.apple.com/HT208696" }, { "type": "WEB", "url": "https://support.apple.com/HT208697" }, { "type": "WEB", "url": "https://usn.ubuntu.com/3635-1" }, { "type": "WEB", "url": "https://www.debian.org/security/2018/dsa-4256" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/104887" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1040604" } ], "schema_version": "1.4.0", "severity": [ { "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "type": "CVSS_V3" } ] }
gsd-2018-4117
Vulnerability from gsd
{ "GSD": { "alias": "CVE-2018-4117", "description": "An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the \"WebKit\" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.", "id": "GSD-2018-4117", "references": [ "https://www.suse.com/security/cve/CVE-2018-4117.html", "https://www.debian.org/security/2018/dsa-4256", "https://access.redhat.com/errata/RHSA-2018:2282", "https://ubuntu.com/security/CVE-2018-4117", "https://advisories.mageia.org/CVE-2018-4117.html" ] }, "gsd": { "metadata": { "exploitCode": "unknown", "remediation": "unknown", "reportConfidence": "confirmed", "type": "vulnerability" }, "osvSchema": { "aliases": [ "CVE-2018-4117" ], "details": "An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the \"WebKit\" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.", "id": "GSD-2018-4117", "modified": "2023-12-13T01:22:28.765703Z", "schema_version": "1.4.0" } }, "namespaces": { "cve.org": { "CVE_data_meta": { "ASSIGNER": "product-security@apple.com", "ID": "CVE-2018-4117", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the \"WebKit\" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "1040604", "refsource": "SECTRACK", "url": "http://www.securitytracker.com/id/1040604" }, { "name": "GLSA-201808-04", "refsource": "GENTOO", "url": "https://security.gentoo.org/glsa/201808-04" }, { "name": "RHSA-2018:2282", "refsource": "REDHAT", "url": "https://access.redhat.com/errata/RHSA-2018:2282" }, { "name": "GLSA-201808-01", "refsource": "GENTOO", "url": "https://security.gentoo.org/glsa/201808-01" }, { "name": "https://support.apple.com/HT208696", "refsource": "CONFIRM", "url": "https://support.apple.com/HT208696" }, { "name": "https://support.apple.com/HT208693", "refsource": "CONFIRM", "url": "https://support.apple.com/HT208693" }, { "name": "DSA-4256", "refsource": "DEBIAN", "url": "https://www.debian.org/security/2018/dsa-4256" }, { "name": "https://support.apple.com/HT208694", "refsource": "CONFIRM", "url": "https://support.apple.com/HT208694" }, { "name": "104887", "refsource": "BID", "url": "http://www.securityfocus.com/bid/104887" }, { "name": "https://support.apple.com/HT208697", "refsource": "CONFIRM", "url": "https://support.apple.com/HT208697" }, { "name": "USN-3635-1", "refsource": "UBUNTU", "url": "https://usn.ubuntu.com/3635-1/" }, { "name": "https://support.apple.com/HT208695", "refsource": "CONFIRM", "url": "https://support.apple.com/HT208695" } ] } }, "nvd.nist.gov": { "configurations": { "CVE_data_version": "4.0", "nodes": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndExcluding": "11.1", "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndExcluding": "11.3", "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndExcluding": "4.3", "vulnerable": true } ], "operator": "OR" }, { "children": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:apple:icloud:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndExcluding": "7.4", "vulnerable": true } ], "operator": "OR" }, { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": false } ], "operator": "OR" } ], "cpe_match": [], "operator": "AND" }, { "children": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndExcluding": "12.7.4", "vulnerable": true } ], "operator": "OR" }, { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": false } ], "operator": "OR" } ], "cpe_match": [], "operator": "AND" }, { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:webkitgtk:webkitgtk\\+:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndExcluding": "2.20.4", "vulnerable": true } ], "operator": "OR" }, { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true } ], "operator": "OR" } ] }, "cve": { "CVE_data_meta": { "ASSIGNER": "product-security@apple.com", "ID": "CVE-2018-4117" }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "en", "value": "An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the \"WebKit\" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "en", "value": "CWE-200" } ] } ] }, "references": { "reference_data": [ { "name": "https://support.apple.com/HT208697", "refsource": "CONFIRM", "tags": [ "Vendor Advisory" ], "url": "https://support.apple.com/HT208697" }, { "name": "https://support.apple.com/HT208696", "refsource": "CONFIRM", "tags": [ "Vendor Advisory" ], "url": "https://support.apple.com/HT208696" }, { "name": "https://support.apple.com/HT208695", "refsource": "CONFIRM", "tags": [ "Vendor Advisory" ], "url": "https://support.apple.com/HT208695" }, { "name": "https://support.apple.com/HT208694", "refsource": "CONFIRM", "tags": [ "Vendor Advisory" ], "url": "https://support.apple.com/HT208694" }, { "name": "https://support.apple.com/HT208693", "refsource": "CONFIRM", "tags": [ "Vendor Advisory" ], "url": "https://support.apple.com/HT208693" }, { "name": "1040604", "refsource": "SECTRACK", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "http://www.securitytracker.com/id/1040604" }, { "name": "USN-3635-1", "refsource": "UBUNTU", "tags": [ "Third Party Advisory" ], "url": "https://usn.ubuntu.com/3635-1/" }, { "name": "DSA-4256", "refsource": "DEBIAN", "tags": [ "Third Party Advisory" ], "url": "https://www.debian.org/security/2018/dsa-4256" }, { "name": "104887", "refsource": "BID", "tags": [ "Third Party Advisory", "VDB Entry" ], "url": "http://www.securityfocus.com/bid/104887" }, { "name": "RHSA-2018:2282", "refsource": "REDHAT", "tags": [ "Third Party Advisory" ], "url": "https://access.redhat.com/errata/RHSA-2018:2282" }, { "name": "GLSA-201808-04", "refsource": "GENTOO", "tags": [ "Third Party Advisory" ], "url": "https://security.gentoo.org/glsa/201808-04" }, { "name": "GLSA-201808-01", "refsource": "GENTOO", "tags": [ "Third Party Advisory" ], "url": "https://security.gentoo.org/glsa/201808-01" } ] } }, "impact": { "baseMetricV2": { "cvssV2": { "accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "version": "2.0" }, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "severity": "MEDIUM", "userInteractionRequired": true }, "baseMetricV3": { "cvssV3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "version": "3.0" }, "exploitabilityScore": 2.8, "impactScore": 3.6 } }, "lastModifiedDate": "2018-11-09T17:58Z", "publishedDate": "2018-04-03T06:29Z" } } }
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.