CVE-2018-6116
published 2018-12-04CVE-2018-6116: A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a…
PriorityP428medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
1.42%
70.1th percentile
A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| chrome | < 66.0.3359.117 | 66.0.3359.117 | |
| chrome | >= unspecified < 66.0.3359.117 | 66.0.3359.117 | |
| redhat | linux_desktop | — | — |
| redhat | linux_server | — | — |
| redhat | linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: Incorrect low memory handling in WebAssembly
vendor_redhat·2018-04-17·CVSS 6.5
CVE-2018-6116 [MEDIUM] chromium-browser: Incorrect low memory handling in WebAssembly
chromium-browser: Incorrect low memory handling in WebAssembly
A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
GHSA
GHSA-5h45-8j9q-c6wv: A nullptr dereference in WebAssembly in Google Chrome prior to 66
ghsa_unreviewed·2022-05-14
CVE-2018-6116 [MEDIUM] CWE-476 GHSA-5h45-8j9q-c6wv: A nullptr dereference in WebAssembly in Google Chrome prior to 66
A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
OSV
CVE-2018-6116: A nullptr dereference in WebAssembly in Google Chrome prior to 66
osv·2018-12-04·CVSS 6.5
CVE-2018-6116 [MEDIUM] CVE-2018-6116: A nullptr dereference in WebAssembly in Google Chrome prior to 66
A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116
bugzilla·2019-02-07·CVSS 7.8
CVE-2019-3839 [HIGH] CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116
CVE-2019-3839 ghostscript: missing attack vector protections for CVE-2019-6116
It was found that some additional operators and dictionaries were needed to be hidden in order to prevent other CVE-2019-6116 attacks.
Discussion:
Mitigation:
Please refer to the "Mitigation" section of CVE-2018-16509 : https://access.redhat.com/security/cve/cve-2018-16509
---
Additional commit required for CVE-2019-6116 :
http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=4ec9ca7
+ http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=db24f25 to prevent pdf2dsc regression
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:0971 https://access.redhat.com/errata/RHSA-2019:0971
---
This issue has been addressed in the following products:
Red
Bugzilla
CVE-2019-6116 ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)
bugzilla·2019-01-16·CVSS 7.8
CVE-2019-6116 [HIGH] CVE-2019-6116 ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)
CVE-2019-6116 ghostscript: subroutines within pseudo-operators must themselves be pseudo-operators (700317)
It was found that operators did not sufficiently protect their calls to other sensitive operators.
An attacker could use this flaw to get access to sensitive operators, such as .forceput, and use these operators to disable the SAFER mode, and for example, get access to the file system outside of the restricted areas.
Discussion:
Mitigation:
Please refer to the "Mitigation" section of CVE-2018-16509 : https://access.redhat.com/security/cve/cve-2018-16509
---
External References:
https://bugs.ghostscript.com/show_bug.cgi?id=700317
---
Acknowledgments:
Name: Tavis Ormandy (Google Project Zero)
---
Created ghostscript tracking bugs for this issue:
Affects: fedora-all [bug 16
Bugzilla
CVE-2018-6116 chromium-browser: Incorrect low memory handling in WebAssembly
bugzilla·2018-04-18·CVSS 6.5
CVE-2018-6116 [MEDIUM] CVE-2018-6116 chromium-browser: Incorrect low memory handling in WebAssembly
CVE-2018-6116 chromium-browser: Incorrect low memory handling in WebAssembly
An incorrect low memory handling flaw was found in the WebAssembly component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=822266
External References:
https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1568801]
Affects: epel-7 [bug 1568800]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1195 https://access.redhat.com/errata/RHSA-2018:1195
http://www.securityfocus.com/bid/103917https://access.redhat.com/errata/RHSA-2018:1195https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.htmlhttps://crbug.com/822266https://security.gentoo.org/glsa/201804-22https://www.debian.org/security/2018/dsa-4182http://www.securityfocus.com/bid/103917https://access.redhat.com/errata/RHSA-2018:1195https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.htmlhttps://crbug.com/822266https://security.gentoo.org/glsa/201804-22https://www.debian.org/security/2018/dsa-4182
2018-12-04
Published