CVE-2018-17466Out-of-bounds Read in Google Chrome

CWE-125Out-of-bounds Read12 documents8 sources
Severity
8.8HIGHNVD
OSV9.8
EPSS
1.1%
top 21.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateMay 14

Description

Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages7 packages

CVEListV5google/chromeunspecified70.0.3538.67
NVDgoogle/chrome< 70.0.3538.67
Ubuntumozilla/firefox< 64.0+build3-0ubuntu0.14.04.1+2
Debianmozilla/thunderbird< 1:60.4.0-1+3

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 18.10, Enterprise Linux 7.6

🔴Vulnerability Details

4
GHSA
GHSA-39c8-xrqg-gq92: Incorrect texture handling in Angle in Google Chrome prior to 702022-05-14
OSV
firefox vulnerabilities2018-12-11
OSV
CVE-2018-17466: Incorrect texture handling in Angle in Google Chrome prior to 702018-11-14
CVEList
CVE-2018-17466: Incorrect texture handling in Angle in Google Chrome prior to 702018-11-14

📋Vendor Advisories

4
Ubuntu
Thunderbird vulnerabilities2019-01-24
Ubuntu
Firefox vulnerabilities2018-12-11
Red Hat
firefox: Memory corruption in Angle2018-10-16
Debian
CVE-2018-17466: firefox - Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allow...2018

💬Community

3
Bugzilla
CVE-2018-16435 CVE-2018-17462 CVE-2018-17463 CVE-2018-17464 CVE-2018-17465 CVE-2018-17466 CVE-2018-17467 CVE-2018-17468 CVE-2018-17469 CVE-2018-17470 CVE-2018-17471 CVE-2018-17473 CVE-2018-17474 CVE-22018-10-17
Bugzilla
CVE-2018-17466 chromium-browser, firefox: Memory corruption in Angle2018-10-17
Bugzilla
CVE-2018-16435 CVE-2018-17462 CVE-2018-17463 CVE-2018-17464 CVE-2018-17465 CVE-2018-17466 CVE-2018-17467 CVE-2018-17468 CVE-2018-17469 CVE-2018-17470 CVE-2018-17471 CVE-2018-17473 CVE-2018-17474 CVE-22018-10-17
CVE-2018-17466 — Out-of-bounds Read in Google Chrome | cvebase