CVE-2018-6075

Severity
6.5MEDIUM
EPSS
0.7%
top 27.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateMay 14

Description

Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

CVEListV5google/chromeunspecified65.0.3325.146
NVDgoogle/chrome< 65.0.3325.146
Ubuntuchromium-browser< 65.0.3325.181-0ubuntu0.14.04.1+1

Also affects: Debian Linux 9.0

🔴Vulnerability Details

3
GHSA
GHSA-p5p7-ccwg-887m: Incorrect handling of specified filenames in file downloads in Google Chrome prior to 652022-05-14
OSV
CVE-2018-6075: Incorrect handling of specified filenames in file downloads in Google Chrome prior to 652018-11-14
CVEList
CVE-2018-6075: Incorrect handling of specified filenames in file downloads in Google Chrome prior to 652018-11-14

📋Vendor Advisories

1
Red Hat
chromium-browser: overly permissive cross origin downloads2018-03-06

💬Community

1
Bugzilla
CVE-2018-6075 chromium-browser: overly permissive cross origin downloads2018-03-07
CVE-2018-6075 (MEDIUM CVSS 6.5) | Incorrect handling of specified fil | cvebase.io