CVE-2018-17466
published 2018-11-14CVE-2018-17466: Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML…
PriorityP344high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.83%
85.1th percentile
Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 64.0-1 (sid) | firefox 64.0-1 (sid) |
| debian | firefox-esr | < firefox 64.0-1 (sid) | firefox 64.0-1 (sid) |
| debian | thunderbird | < firefox 64.0-1 (sid) | firefox 64.0-1 (sid) |
| chrome | < 70.0.3538.67 | 70.0.3538.67 | |
| chrome | >= unspecified < 70.0.3538.67 | 70.0.3538.67 | |
| mozilla | firefox | >= 0 < 64.0+build3-0ubuntu0.14.04.1 | 64.0+build3-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 64.0+build3-0ubuntu0.16.04.1 | 64.0+build3-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 64.0+build3-0ubuntu0.18.04.1 | 64.0+build3-0ubuntu0.18.04.1 |
| mozilla | thunderbird | >= 0 < 1:60.4.0-1 | 1:60.4.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.4.0-1 | 1:60.4.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.4.0-1 | 1:60.4.0-1 |
| mozilla | thunderbird | >= 0 < 1:60.4.0-1 | 1:60.4.0-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-39c8-xrqg-gq92: Incorrect texture handling in Angle in Google Chrome prior to 70
ghsa_unreviewed·2022-05-14
CVE-2018-17466 [HIGH] CWE-125 GHSA-39c8-xrqg-gq92: Incorrect texture handling in Angle in Google Chrome prior to 70
Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
OSV
firefox vulnerabilities
osv·2018-12-11·CVSS 9.8
CVE-2018-12405 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, bypass same-origin
restritions, or execute arbitrary code. (CVE-2018-12405, CVE-2018-12406,
CVE-2018-12407, CVE-2018-17466, CVE-2018-18492, CVE-2018-18493,
CVE-2018-18494, CVE-2018-18498)
Multiple security issues were discovered in WebExtensions. If a user were
tricked in to installing a specially crafted extension, an attacker could
potentially exploit these to open privileged pages, or bypass other
security restrictions. (CVE-2018-18495, CVE-2018-18497)
OSV
CVE-2018-17466: Incorrect texture handling in Angle in Google Chrome prior to 70
osv·2018-11-14·CVSS 8.8
CVE-2018-17466 [HIGH] CVE-2018-17466: Incorrect texture handling in Angle in Google Chrome prior to 70
Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2019-01-24
CVE-2018-12389 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
bypass same-origin restrictions, or execute arbitrary code.
Instructions: After a standard system update you need to restart Thunderbird to make
all the necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2018-12-11·CVSS 9.8
CVE-2018-12405 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, bypass same-origin
restritions, or execute arbitrary code. (CVE-2018-12405, CVE-2018-12406,
CVE-2018-12407, CVE-2018-17466, CVE-2018-18492, CVE-2018-18493,
CVE-2018-18494, CVE-2018-18498)
Multiple security issues were discovered in WebExtensions. If a user were
tricked in to installing a specially crafted extension, an attacker could
potentially exploit these to open privileged pages, or bypass other
security restrictions. (CVE-2018-18495, CVE-2018-18497)
Instruct
Red Hat
firefox: Memory corruption in Angle
vendor_redhat·2018-10-16·CVSS 8.8
CVE-2018-17466 [HIGH] firefox: Memory corruption in Angle
firefox: Memory corruption in Angle
Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Statement: In general, this flaw be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-17466: firefox - Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allow...
vendor_debian·2018·CVSS 8.8
CVE-2018-17466 [HIGH] CVE-2018-17466: firefox - Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allow...
Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Scope: local
sid: resolved (fixed in 64.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16435 CVE-2018-17462 CVE-2018-17463 CVE-2018-17464 CVE-2018-17465 CVE-2018-17466 CVE-2018-17467 CVE-2018-17468 CVE-2018-17469 CVE-2018-17470 CVE-2018-17471 CVE-2018-17473 CVE-2018-17474 CVE-2
bugzilla·2018-10-17·CVSS 5.5
CVE-2018-16435 [MEDIUM] CVE-2018-16435 CVE-2018-17462 CVE-2018-17463 CVE-2018-17464 CVE-2018-17465 CVE-2018-17466 CVE-2018-17467 CVE-2018-17468 CVE-2018-17469 CVE-2018-17470 CVE-2018-17471 CVE-2018-17473 CVE-2018-17474 CVE-2
CVE-2018-16435 CVE-2018-17462 CVE-2018-17463 CVE-2018-17464 CVE-2018-17465 CVE-2018-17466 CVE-2018-17467 CVE-2018-17468 CVE-2018-17469 CVE-2018-17470 CVE-2018-17471 CVE-2018-17473 CVE-2018-17474 CVE-2018-17475 ... chromium: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-l
Bugzilla
CVE-2018-17466 chromium-browser, firefox: Memory corruption in Angle
bugzilla·2018-10-17·CVSS 8.8
CVE-2018-17466 [HIGH] CVE-2018-17466 chromium-browser, firefox: Memory corruption in Angle
CVE-2018-17466 chromium-browser, firefox: Memory corruption in Angle
A memory corruption flaw was found in the Angle component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=880906
External References:
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1640122]
Affects: fedora-all [bug 1640121]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:3004 https://access.redhat.com/errata/RHSA-2018:3004
---
This flaw also affected Firefox 60.3 ESR:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-30/#CVE-2018-17466
---
This issue has been addressed
Bugzilla
CVE-2018-16435 CVE-2018-17462 CVE-2018-17463 CVE-2018-17464 CVE-2018-17465 CVE-2018-17466 CVE-2018-17467 CVE-2018-17468 CVE-2018-17469 CVE-2018-17470 CVE-2018-17471 CVE-2018-17473 CVE-2018-17474 CVE-2
bugzilla·2018-10-17·CVSS 5.5
CVE-2018-16435 [MEDIUM] CVE-2018-16435 CVE-2018-17462 CVE-2018-17463 CVE-2018-17464 CVE-2018-17465 CVE-2018-17466 CVE-2018-17467 CVE-2018-17468 CVE-2018-17469 CVE-2018-17470 CVE-2018-17471 CVE-2018-17473 CVE-2018-17474 CVE-2
CVE-2018-16435 CVE-2018-17462 CVE-2018-17463 CVE-2018-17464 CVE-2018-17465 CVE-2018-17466 CVE-2018-17467 CVE-2018-17468 CVE-2018-17469 CVE-2018-17470 CVE-2018-17471 CVE-2018-17473 CVE-2018-17474 CVE-2018-17475 ... chromium: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the releva
Bugzilla
heap overflow in TextureStorage11 - ANGLE
bugzilla·2018-09-03
[MEDIUM] heap overflow in TextureStorage11 - ANGLE
heap overflow in TextureStorage11 - ANGLE
Created attachment 9006107
texstor11.html
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0) Gecko/20100101 Firefox/61.0
Build ID: 20180807170231
Steps to reproduce:
Attached is the testcase to reproduce a heap overflow in TexStorage11 in Firefox 61.0.2.
I have tested this on Intel and Nvidia GPU, both crash due to the same invalid pixelData buffer reference.
Actual results:
5:202> r
rax=00007ffd57ca1034 rbx=000001eeeaa00000 rcx=000001eeeaa00000
rdx=00000236f87c90d0 rsi=00000236f87c90d0 rdi=0000000000000004
rip=00007ffd57ca1034 rsp=00000048125fb2f8 rbp=0000000000000001
r8=0000000000000004 r9=00007ffd57c80000 r10=000001eeeaa00000
r11=000001eeeaa00000 r12=000001eee1c01d58 r13=0000000000000000
r14=0000000000000040 r15=00000000000000
http://www.securityfocus.com/bid/105666http://www.securityfocus.com/bid/106168https://access.redhat.com/errata/RHSA-2018:3004https://access.redhat.com/errata/RHSA-2018:3831https://access.redhat.com/errata/RHSA-2018:3833https://access.redhat.com/errata/RHSA-2019:0159https://access.redhat.com/errata/RHSA-2019:0160https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.htmlhttps://crbug.com/880906https://lists.debian.org/debian-lts-announce/2018/12/msg00002.htmlhttps://security.gentoo.org/glsa/201811-10https://usn.ubuntu.com/3844-1/https://usn.ubuntu.com/3868-1/https://www.debian.org/security/2018/dsa-4330https://www.debian.org/security/2018/dsa-4354https://www.debian.org/security/2019/dsa-4362http://www.securityfocus.com/bid/105666http://www.securityfocus.com/bid/106168https://access.redhat.com/errata/RHSA-2018:3004https://access.redhat.com/errata/RHSA-2018:3831https://access.redhat.com/errata/RHSA-2018:3833https://access.redhat.com/errata/RHSA-2019:0159https://access.redhat.com/errata/RHSA-2019:0160https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.htmlhttps://crbug.com/880906https://lists.debian.org/debian-lts-announce/2018/12/msg00002.htmlhttps://security.gentoo.org/glsa/201811-10https://usn.ubuntu.com/3844-1/https://usn.ubuntu.com/3868-1/https://www.debian.org/security/2018/dsa-4330https://www.debian.org/security/2018/dsa-4354https://www.debian.org/security/2019/dsa-4362
2018-11-14
Published