Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title chromium-browser security update
Informations
Name DSA-4289 First vendor Publication 2018-09-07
Vendor Debian Last vendor Modification 2018-09-07
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 6.8 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Several vulnerabilities have been discovered in the chromium web browser.

CVE-2018-16065

Brendon Tiszka discovered an out-of-bounds write issue in the v8 javascript library.

CVE-2018-16066

cloudfuzzer discovered an out-of-bounds read issue in blink/webkit.

CVE-2018-16067

Zhe Jin discovered an out-of-bounds read issue in the WebAudio implementation.

CVE-2018-16068

Mark Brand discovered an out-of-bounds write issue in the Mojo message passing library.

CVE-2018-16069

Mark Brand discovered an out-of-bounds read issue in the swiftshader library.

CVE-2018-16070

Ivan Fratric discovered an integer overflow issue in the skia library.

CVE-2018-16071

Natalie Silvanovich discovered a use-after-free issue in the WebRTC implementation.

CVE-2018-16073

Jun Kokatsu discovered an error in the Site Isolation feature when restoring browser tabs.

CVE-2018-16074

Jun Kokatsu discovered an error in the Site Isolation feature when using a Blob URL.

CVE-2018-16075

Pepe Vila discovered an error that could allow remote sites to access local files.

CVE-2018-16076

Aseksandar Nikolic discovered an out-of-bounds read issue in the pdfium library.

CVE-2018-16077

Manuel Caballero discovered a way to bypass the Content Security Policy.

CVE-2018-16078

Cailan Sacks discovered that the Autofill feature could leak saved credit card information.

CVE-2018-16079

Markus Vervier and Michele Orrù discovered a URL spoofing issue.

CVE-2018-16080

Khalil Zhani discovered a URL spoofing issue.

CVE-2018-16081

Jann Horn discovered that local files could be accessed in the developer tools.

CVE-2018-16082

Omair discovered a buffer overflow issue in the swiftshader library.

CVE-2018-16083

Natalie Silvanovich discovered an out-of-bounds read issue in the WebRTC implementation.

CVE-2018-16084

Jun Kokatsu discovered a way to bypass a user confirmation dialog.

CVE-2018-16085

Roman Kuksin discovered a use-after-free issue.

For the stable distribution (stretch), these problems have been fixed in version 69.0.3497.81-1~deb9u1.

We recommend that you upgrade your chromium-browser packages.

For the detailed security status of chromium-browser please refer to its security tracker page at: https://security-tracker.debian.org/tracker/chromium-browser

Original Source

Url : http://www.debian.org/security/2018/dsa-4289

CWE : Common Weakness Enumeration

% Id Name
22 % CWE-787 Out-of-bounds Write (CWE/SANS Top 25)
22 % CWE-416 Use After Free
17 % CWE-125 Out-of-bounds Read
13 % CWE-285 Improper Access Control (Authorization)
9 % CWE-20 Improper Input Validation
4 % CWE-362 Race Condition
4 % CWE-200 Information Exposure
4 % CWE-190 Integer Overflow or Wraparound (CWE/SANS Top 25)
4 % CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25)

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 4273
Os 1
Os 4
Os 1
Os 1
Os 1

Nessus® Vulnerability Scanner

Date Description
2019-01-03 Name : The remote Fedora host is missing a security update.
File : fedora_2018-13d8c35127.nasl - Type : ACT_GATHER_INFO
2019-01-03 Name : The remote Fedora host is missing a security update.
File : fedora_2018-39be36e9fc.nasl - Type : ACT_GATHER_INFO
2018-11-26 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201811-10.nasl - Type : ACT_GATHER_INFO
2018-09-24 Name : The remote Fedora host is missing a security update.
File : fedora_2018-4a16e37c81.nasl - Type : ACT_GATHER_INFO
2018-09-10 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-4289.nasl - Type : ACT_GATHER_INFO
2018-09-06 Name : A web browser installed on the remote Windows host is affected by multiple vu...
File : google_chrome_69_0_3497_81.nasl - Type : ACT_GATHER_INFO
2018-09-06 Name : A web browser installed on the remote macOS host is affected by multiple vuln...
File : macosx_google_chrome_69_0_3497_81.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
Date Informations
2019-10-03 09:24:28
  • Multiple Updates
2019-01-15 17:21:44
  • Multiple Updates
2019-01-10 17:21:20
  • Multiple Updates
2018-09-08 09:20:59
  • First insertion