Un integer overflow nella gestione percorso portato ad un uso dopo gratuito in Skia in Google Chrome 71.0.3578.80 prima di permesso un attaccante remoto di sfruttare potenzialmente danneggiamento di heap attraverso una pagina HTML artigianale. |
http://www.securityfocus.com/bid/106084 https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html https://www.debian.org/security/2018/dsa-4352 https://www.debian.org/security/2019/dsa-4391 https://www.debian.org/security/2019/dsa-4392 https://security.gentoo.org/glsa/201903-04 https://security.gentoo.org/glsa/201904-07 https://security.gentoo.org/glsa/201908-18 https://crbug.com/883666 https://lists.debian.org/debian-lts-announce/2019/02/msg00023.html https://lists.debian.org/debian-lts-announce/2019/02/msg00024.html https://access.redhat.com/errata/RHSA-2018:3803 https://access.redhat.com/errata/RHSA-2019:0373 https://access.redhat.com/errata/RHSA-2019:0374 https://access.redhat.com/errata/RHSA-2019:1144 http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00043.html https://usn.ubuntu.com/3896-1/ https://usn.ubuntu.com/3897-1/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18356 |
Vulnerabilità: CVE-2018-18356
