CVE-2018-0484
published 2019-01-10CVE-2018-0484: A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual…
PriorityP336medium6.5CVSS 3.0
AVNACLPRLUINSUCNIHAN
EPSS
0.79%
51.9th percentile
A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class configuration. The vulnerability is due to a missing check in the SSH server. An attacker could use this vulnerability to open an SSH connection to an affected Cisco IOS or IOS XE device with a source address belonging to a VRF instance. Once connected, the attacker would still need to provide valid credentials to access the device.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_and_ios_xe | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wpcx-9mmv-mm42: A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a vir
ghsa_unreviewed·2022-05-13
CVE-2018-0484 [MEDIUM] GHSA-wpcx-9mmv-mm42: A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a vir
A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class configuration. The vulnerability is due to a missing check in the SSH server. An attacker could use this vulnerability to open an SSH connection to an affected Cisco IOS or IOS XE device with a source address belonging to a VRF instance. Once connected, the attacker would still need to provide valid credentials to access the device.
Cisco
Cisco IOS and IOS XE Software Secure Shell Connection on VRF Vulnerability
vendor_cisco·2019-01-09·CVSS 5.3
CVE-2018-0484 [MEDIUM] CWE-284 Cisco IOS and IOS XE Software Secure Shell Connection on VRF Vulnerability
Cisco IOS and IOS XE Software Secure Shell Connection on VRF Vulnerability
A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class configuration.
The vulnerability is due to a missing check in the SSH server. An attacker could use this vulnerability to open an SSH connection to an affected Cisco IOS or IOS XE device with a source address belonging to a VRF instance. Once connected, the attacker would still need to provide valid credentials to access the device.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.c
Cisco
Cisco IOS and IOS XE Software Secure Shell Connection on VRF Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0484 Cisco IOS and IOS XE Software Secure Shell Connection on VRF Vulnerability
CVE-2018-0484: Cisco IOS and IOS XE Software Secure Shell Connection on VRF Vulnerability
A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class configuration. The vulnerability is due to a missing check in the SSH server. An attacker could use this vulnerability to open an SSH connection to an affected Cisco IOS or IOS XE device with a source address belonging to a VRF instance. Once connected, the attacker would still need to provide valid credentials to access the device. There are no
CVSS: 3.0
CWE: CWE-284, CWE-284
Bug IDs: CSCvk37852
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-6060 chromium-browser: use-after-free in blink
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-6060 [HIGH] CVE-2018-6060 chromium-browser: use-after-free in blink
CVE-2018-6060 chromium-browser: use-after-free in blink
An use after free flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=780919
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6070 chromium-browser: csp bypass through extensions
bugzilla·2018-03-07·CVSS 6.1
CVE-2018-6070 [MEDIUM] CVE-2018-6070 chromium-browser: csp bypass through extensions
CVE-2018-6070 chromium-browser: csp bypass through extensions
The following flaw was identified in the Chromium browser: csp bypass through extensions.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=668645
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6078 chromium-browser: url spoof in omnibox
bugzilla·2018-03-07·CVSS 4.3
CVE-2018-6078 [MEDIUM] CVE-2018-6078 chromium-browser: url spoof in omnibox
CVE-2018-6078 chromium-browser: url spoof in omnibox
An url spoof flaw was found in the OmniBox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=793628
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6081 chromium-browser: xss in interstitials
bugzilla·2018-03-07·CVSS 6.1
CVE-2018-6081 [MEDIUM] CVE-2018-6081 chromium-browser: xss in interstitials
CVE-2018-6081 chromium-browser: xss in interstitials
A xss flaw was found in the interstitials component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=797525
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6077 chromium-browser: timing attack using svg filters
bugzilla·2018-03-07·CVSS 6.5
CVE-2018-6077 [MEDIUM] CVE-2018-6077 chromium-browser: timing attack using svg filters
CVE-2018-6077 chromium-browser: timing attack using svg filters
The following flaw was identified in the Chromium browser: timing attack using svg filters.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=778506
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6063 chromium-browser: incorrect permissions on shared memory
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-6063 [HIGH] CVE-2018-6063 chromium-browser: incorrect permissions on shared memory
CVE-2018-6063 chromium-browser: incorrect permissions on shared memory
The following flaw was identified in the Chromium browser: incorrect permissions on shared memory.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=792900
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6067 chromium-browser: buffer overflow in skia
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-6067 [HIGH] CVE-2018-6067 chromium-browser: buffer overflow in skia
CVE-2018-6067 chromium-browser: buffer overflow in skia
A buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=779428
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6075 chromium-browser: overly permissive cross origin downloads
bugzilla·2018-03-07·CVSS 6.5
CVE-2018-6075 [MEDIUM] CVE-2018-6075 chromium-browser: overly permissive cross origin downloads
CVE-2018-6075 chromium-browser: overly permissive cross origin downloads
The following flaw was identified in the Chromium browser: overly permissive cross origin downloads.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=608669
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6079 chromium-browser: information disclosure via texture data in webgl
bugzilla·2018-03-07·CVSS 6.5
CVE-2018-6079 [MEDIUM] CVE-2018-6079 chromium-browser: information disclosure via texture data in webgl
CVE-2018-6079 chromium-browser: information disclosure via texture data in webgl
An information disclosure via texture data flaw was found in the WebGL component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=788448
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6073 chromium-browser: heap bufffer overflow in webgl
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-6073 [HIGH] CVE-2018-6073 chromium-browser: heap bufffer overflow in webgl
CVE-2018-6073 chromium-browser: heap bufffer overflow in webgl
A heap bufffer overflow flaw was found in the WebGL component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=804118
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6061 chromium-browser: race condition in v8
bugzilla·2018-03-07·CVSS 7.5
CVE-2018-6061 [HIGH] CVE-2018-6061 chromium-browser: race condition in v8
CVE-2018-6061 chromium-browser: race condition in v8
A race condition flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=794091
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6074 chromium-browser: mark-of-the-web bypass
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-6074 [HIGH] CVE-2018-6074 chromium-browser: mark-of-the-web bypass
CVE-2018-6074 chromium-browser: mark-of-the-web bypass
The following flaw was identified in the Chromium browser: mark-of-the-web bypass.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=809759
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6065 chromium-browser: integer overflow in v8
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-6065 [HIGH] CVE-2018-6065 chromium-browser: integer overflow in v8
CVE-2018-6065 chromium-browser: integer overflow in v8
An integer overflow flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=808192
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6064 chromium-browser: type confusion in v8
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-6064 [HIGH] CVE-2018-6064 chromium-browser: type confusion in v8
CVE-2018-6064 chromium-browser: type confusion in v8
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=798644
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6066 chromium-browser: same origin bypass via canvas
bugzilla·2018-03-07·CVSS 6.5
CVE-2018-6066 [MEDIUM] CVE-2018-6066 chromium-browser: same origin bypass via canvas
CVE-2018-6066 chromium-browser: same origin bypass via canvas
The following flaw was identified in the Chromium browser: same origin bypass via canvas.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=799477
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6076 chromium-browser: incorrect handling of url fragment identifiers in blink
bugzilla·2018-03-07·CVSS 6.1
CVE-2018-6076 [MEDIUM] CVE-2018-6076 chromium-browser: incorrect handling of url fragment identifiers in blink
CVE-2018-6076 chromium-browser: incorrect handling of url fragment identifiers in blink
An incorrect handling of url fragment identifiers flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=758523
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6080 chromium-browser: information disclosure in ipc call
bugzilla·2018-03-07·CVSS 6.5
CVE-2018-6080 [MEDIUM] CVE-2018-6080 chromium-browser: information disclosure in ipc call
CVE-2018-6080 chromium-browser: information disclosure in ipc call
An information disclosure flaw was found in the IPC call component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=792028
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6069 chromium-browser: stack buffer overflow in skia
bugzilla·2018-03-07·CVSS 6.5
CVE-2018-6069 [MEDIUM] CVE-2018-6069 chromium-browser: stack buffer overflow in skia
CVE-2018-6069 chromium-browser: stack buffer overflow in skia
A stack buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=799918
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6083 chromium-browser: incorrect processing of appmanifests
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-6083 [HIGH] CVE-2018-6083 chromium-browser: incorrect processing of appmanifests
CVE-2018-6083 chromium-browser: incorrect processing of appmanifests
The following flaw was identified in the Chromium browser: incorrect processing of appmanifests.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=771709
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6062 chromium-browser: heap buffer overflow in skia
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-6062 [HIGH] CVE-2018-6062 chromium-browser: heap buffer overflow in skia
CVE-2018-6062 chromium-browser: heap buffer overflow in skia
A heap buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=780104
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6071 chromium-browser: heap bufffer overflow in skia
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-6071 [HIGH] CVE-2018-6071 chromium-browser: heap bufffer overflow in skia
CVE-2018-6071 chromium-browser: heap bufffer overflow in skia
A heap bufffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=777318
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6057 chromium-browser: incorrect permissions on shared memory
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-6057 [HIGH] CVE-2018-6057 chromium-browser: incorrect permissions on shared memory
CVE-2018-6057 chromium-browser: incorrect permissions on shared memory
The following flaw was identified in the Chromium browser: incorrect permissions on shared memory.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=789959
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6082 chromium-browser: circumvention of port blocking
bugzilla·2018-03-07·CVSS 4.7
CVE-2018-6082 [MEDIUM] CVE-2018-6082 chromium-browser: circumvention of port blocking
CVE-2018-6082 chromium-browser: circumvention of port blocking
The following flaw was identified in the Chromium browser: circumvention of port blocking.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=767354
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
Bugzilla
CVE-2018-6072 chromium-browser: integer overflow in pdfium
bugzilla·2018-03-07·CVSS 8.8
CVE-2018-6072 [HIGH] CVE-2018-6072 chromium-browser: integer overflow in pdfium
CVE-2018-6072 chromium-browser: integer overflow in pdfium
An integer overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=791048
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:0484 https://access.redhat.com/errata/RHSA-2018:0484
2019-01-10
Published