CVE-2018-1815
published 2018-12-13CVE-2018-1815: IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is vulnerable to cross-site scripting. This…
PriorityP425medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.89%
55.3th percentile
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150019.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_access_manager | 9.0.1.0 – 9.0.5.0 | — |
| ibm | security_access_manager_appliance | — | — |
| ibm | security_access_manager_appliance | — | — |
| ibm | security_access_manager_appliance | — | — |
| ibm | security_access_manager_appliance | — | — |
| ibm | security_access_manager_appliance | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5jwj-52w4-wq5q: IBM Security Access Manager Appliance 9
ghsa_unreviewed·2022-05-13
CVE-2018-1815 [MEDIUM] CWE-79 GHSA-5jwj-52w4-wq5q: IBM Security Access Manager Appliance 9
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 for Enterprise Single-Sign On is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150019.
Cisco
Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability
vendor_cisco·2018-05-02·CVSS 4.1
CVE-2018-0250 [MEDIUM] CWE-693 Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability
Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability
A vulnerability in Central Web Authentication (CWA) with FlexConnect Access Points (APs) for Cisco Aironet 1560, 1810, 1810w, 1815, 1830, 1850, 2800, and 3800 Series APs could allow an authenticated, adjacent attacker to bypass a configured FlexConnect access control list (ACL).
The vulnerability is due to the AP ignoring the ACL download from the client during authentication. An attacker could exploit this vulnerability by connecting to the targeted device with a vulnerable configuration. A successful exploit could allow the attacker to bypass a configured client FlexConnect ACL.
There are workarounds that address this vulnerability.
This advisory is available at the following link:
http
Cisco
Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0250 Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability
CVE-2018-0250: Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability
A vulnerability in Central Web Authentication (CWA) with FlexConnect Access Points (APs) for Cisco Aironet 1560, 1810, 1810w, 1815, 1830, 1850, 2800, and 3800 Series APs could allow an authenticated, adjacent attacker to bypass a configured FlexConnect access control list (ACL). The vulnerability is due to the AP ignoring the ACL download from the client during authentication. An attacker could exploit this vulnerability by connecting to the targeted device with a vulnerable configuration. A successful exploit could allow the attacker to bypass a configured client FlexConnect ACL. There are
CVSS: 3.0
CWE: CWE-693, CWE-693
Bug IDs: CSCve17756
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-6131 chromium-browser: Incorrect mutability protection in WebAssembly
bugzilla·2018-05-30·CVSS 8.8
CVE-2018-6131 [HIGH] CVE-2018-6131 chromium-browser: Incorrect mutability protection in WebAssembly
CVE-2018-6131 chromium-browser: Incorrect mutability protection in WebAssembly
An incorrect mutability protection flaw was found in the WebAssembly component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=826434
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6135 chromium-browser: UI spoofing in Blink
bugzilla·2018-05-30·CVSS 6.5
CVE-2018-6135 [MEDIUM] CVE-2018-6135 chromium-browser: UI spoofing in Blink
CVE-2018-6135 chromium-browser: UI spoofing in Blink
An ui spoofing flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=823353
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6126 Skia: Heap buffer overflow rasterizing paths in SVG
bugzilla·2018-05-30·CVSS 8.8
CVE-2018-6126 [HIGH] CVE-2018-6126 Skia: Heap buffer overflow rasterizing paths in SVG
CVE-2018-6126 Skia: Heap buffer overflow rasterizing paths in SVG
A heap buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=844457
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
---
Mozilla Firefox ESR 52 and ESR 60 are also vulnerable.
Upstream Advisory:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-14/
---
Created
Bugzilla
CVE-2018-6138 chromium-browser: Overly permissive policy in Extensions
bugzilla·2018-05-30·CVSS 8.1
CVE-2018-6138 [HIGH] CVE-2018-6138 chromium-browser: Overly permissive policy in Extensions
CVE-2018-6138 chromium-browser: Overly permissive policy in Extensions
An overly permissive policy flaw was found in the Extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=810220
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6133 chromium-browser: URL spoof in Omnibox
bugzilla·2018-05-30·CVSS 6.5
CVE-2018-6133 [MEDIUM] CVE-2018-6133 chromium-browser: URL spoof in Omnibox
CVE-2018-6133 chromium-browser: URL spoof in Omnibox
An url spoof flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=817247
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6132 chromium-browser: Use of uninitialized memory in WebRTC
bugzilla·2018-05-30·CVSS 4.3
CVE-2018-6132 [MEDIUM] CVE-2018-6132 chromium-browser: Use of uninitialized memory in WebRTC
CVE-2018-6132 chromium-browser: Use of uninitialized memory in WebRTC
An use of uninitialized memory flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=839960
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6142 chromium-browser: Out of bounds memory access in V8
bugzilla·2018-05-30·CVSS 6.5
CVE-2018-6142 [MEDIUM] CVE-2018-6142 chromium-browser: Out of bounds memory access in V8
CVE-2018-6142 chromium-browser: Out of bounds memory access in V8
An out of bounds memory access flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=837939
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6134 chromium-browser: Referrer Policy bypass in Blink
bugzilla·2018-05-30·CVSS 6.5
CVE-2018-6134 [MEDIUM] CVE-2018-6134 chromium-browser: Referrer Policy bypass in Blink
CVE-2018-6134 chromium-browser: Referrer Policy bypass in Blink
A referrer policy bypass flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=797465
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6144 chromium-browser: Out of bounds memory access in PDFium
bugzilla·2018-05-30·CVSS 8.8
CVE-2018-6144 [HIGH] CVE-2018-6144 chromium-browser: Out of bounds memory access in PDFium
CVE-2018-6144 chromium-browser: Out of bounds memory access in PDFium
An out of bounds memory access flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=828049
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6145 chromium-browser: Incorrect escaping of MathML in Blink
bugzilla·2018-05-30·CVSS 6.1
CVE-2018-6145 [MEDIUM] CVE-2018-6145 chromium-browser: Incorrect escaping of MathML in Blink
CVE-2018-6145 chromium-browser: Incorrect escaping of MathML in Blink
An incorrect escaping of mathml flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=805924
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6124 chromium-browser: Type confusion in Blink
bugzilla·2018-05-30·CVSS 8.8
CVE-2018-6124 [HIGH] CVE-2018-6124 chromium-browser: Type confusion in Blink
CVE-2018-6124 chromium-browser: Type confusion in Blink
A type confusion flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=840320
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6143 chromium-browser: Out of bounds memory access in V8
bugzilla·2018-05-30·CVSS 6.5
CVE-2018-6143 [MEDIUM] CVE-2018-6143 chromium-browser: Out of bounds memory access in V8
CVE-2018-6143 chromium-browser: Out of bounds memory access in V8
An out of bounds memory access flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=843022
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6139 chromium-browser: Restrictions bypass in the debugger extension API
bugzilla·2018-05-30·CVSS 8.8
CVE-2018-6139 [HIGH] CVE-2018-6139 chromium-browser: Restrictions bypass in the debugger extension API
CVE-2018-6139 chromium-browser: Restrictions bypass in the debugger extension API
A restrictions bypass flaw was found in the the debugger extension API component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=805224
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6147 chromium-browser: Password fields not taking advantage of OS protections in Views
bugzilla·2018-05-30·CVSS 5.5
CVE-2018-6147 [MEDIUM] CVE-2018-6147 chromium-browser: Password fields not taking advantage of OS protections in Views
CVE-2018-6147 chromium-browser: Password fields not taking advantage of OS protections in Views
A password fields not taking advantage of os protections flaw was found in the Views component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=818133
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6136 chromium-browser: Out of bounds memory access in V8
bugzilla·2018-05-30·CVSS 6.5
CVE-2018-6136 [MEDIUM] CVE-2018-6136 chromium-browser: Out of bounds memory access in V8
CVE-2018-6136 chromium-browser: Out of bounds memory access in V8
An out of bounds memory access flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=831943
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6130 chromium-browser: Out of bounds memory access in WebRTC
bugzilla·2018-05-30·CVSS 6.5
CVE-2018-6130 [MEDIUM] CVE-2018-6130 chromium-browser: Out of bounds memory access in WebRTC
CVE-2018-6130 chromium-browser: Out of bounds memory access in WebRTC
An out of bounds memory access flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=838402
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6125 chromium-browser: Overly permissive policy in WebUSB
bugzilla·2018-05-30·CVSS 6.5
CVE-2018-6125 [MEDIUM] CVE-2018-6125 chromium-browser: Overly permissive policy in WebUSB
CVE-2018-6125 chromium-browser: Overly permissive policy in WebUSB
An overly permissive policy flaw was found in the WebUSB component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=818592
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6137 chromium-browser: Leak of visited status of page in Blink
bugzilla·2018-05-30·CVSS 6.5
CVE-2018-6137 [MEDIUM] CVE-2018-6137 chromium-browser: Leak of visited status of page in Blink
CVE-2018-6137 chromium-browser: Leak of visited status of page in Blink
A leak of visited status of page flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=835589
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6127 chromium-browser: Use after free in indexedDB
bugzilla·2018-05-30·CVSS 9.6
CVE-2018-6127 [CRITICAL] CVE-2018-6127 chromium-browser: Use after free in indexedDB
CVE-2018-6127 chromium-browser: Use after free in indexedDB
An use after free flaw was found in the indexedDB component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=842990
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6123 chromium-browser: Use after free in Blink
bugzilla·2018-05-30·CVSS 6.5
CVE-2018-6123 [MEDIUM] CVE-2018-6123 chromium-browser: Use after free in Blink
CVE-2018-6123 chromium-browser: Use after free in Blink
An use after free flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=835639
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6140 chromium-browser: Restrictions bypass in the debugger extension API
bugzilla·2018-05-30·CVSS 8.8
CVE-2018-6140 [HIGH] CVE-2018-6140 chromium-browser: Restrictions bypass in the debugger extension API
CVE-2018-6140 chromium-browser: Restrictions bypass in the debugger extension API
A restrictions bypass flaw was found in the the debugger extension API component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=798222
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6141 chromium-browser: Heap buffer overflow in Skia
bugzilla·2018-05-30·CVSS 8.8
CVE-2018-6141 [HIGH] CVE-2018-6141 chromium-browser: Heap buffer overflow in Skia
CVE-2018-6141 chromium-browser: Heap buffer overflow in Skia
A heap buffer overflow flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=796107
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
Bugzilla
CVE-2018-6129 chromium-browser: Out of bounds memory access in WebRTC
bugzilla·2018-05-30·CVSS 6.5
CVE-2018-6129 [MEDIUM] CVE-2018-6129 chromium-browser: Out of bounds memory access in WebRTC
CVE-2018-6129 chromium-browser: Out of bounds memory access in WebRTC
An out of bounds memory access flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=838672
External References:
https://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop_58.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1584060]
Affects: fedora-all [bug 1584059]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1815 https://access.redhat.com/errata/RHSA-2018:1815
2018-12-13
Published