Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title chromium-browser security update
Informations
Name DSA-4256 First vendor Publication 2018-07-26
Vendor Debian Last vendor Modification 2018-07-26
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 6.8 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Several vulnerabilities have been discovered in the chromium web browser.

CVE-2018-4117

AhsanEjaz discovered an information leak.

CVE-2018-6044

Rob Wu discovered a way to escalate privileges using extensions.

CVE-2018-6150

Rob Wu discovered an information disclosure issue (this problem was fixed in a previous release but was mistakenly omitted from upstream's announcement at the time).

CVE-2018-6151

Rob Wu discovered an issue in the developer tools (this problem was fixed in a previous release but was mistakenly omitted from upstream's announcement at the time).

CVE-2018-6152

Rob Wu discovered an issue in the developer tools (this problem was fixed in a previous release but was mistakenly omitted from upstream's announcement at the time).

CVE-2018-6153

Zhen Zhou discovered a buffer overflow issue in the skia library.

CVE-2018-6154

Omair discovered a buffer overflow issue in the WebGL implementation.

CVE-2018-6155

Natalie Silvanovich discovered a use-after-free issue in the WebRTC implementation.

CVE-2018-6156

Natalie Silvanovich discovered a buffer overflow issue in the WebRTC implementation.

CVE-2018-6157

Natalie Silvanovich discovered a type confusion issue in the WebRTC implementation.

CVE-2018-6158

Zhe Jin discovered a use-after-free issue.

CVE-2018-6159

Jun Kokatsu discovered a way to bypass the same origin policy.

CVE-2018-6161

Jun Kokatsu discovered a way to bypass the same origin policy.

CVE-2018-6162

Omair discovered a buffer overflow issue in the WebGL implementation.

CVE-2018-6163

Khalil Zhani discovered a URL spoofing issue.

CVE-2018-6164

Jun Kokatsu discovered a way to bypass the same origin policy.

CVE-2018-6165

evil1m0 discovered a URL spoofing issue.

CVE-2018-6166

Lynas Zhang discovered a URL spoofing issue.

CVE-2018-6167

Lynas Zhang discovered a URL spoofing issue.

CVE-2018-6168

Gunes Acar and Danny Y. Huang discovered a way to bypass the Cross Origin Resource Sharing policy.

CVE-2018-6169

Sam P discovered a way to bypass permissions when installing extensions.

CVE-2018-6170

A type confusion issue was discovered in the pdfium library.

CVE-2018-6171

A use-after-free issue was discovered in the WebBluetooth implementation.

CVE-2018-6172

Khalil Zhani discovered a URL spoofing issue.

CVE-2018-6173

Khalil Zhani discovered a URL spoofing issue.

CVE-2018-6174

Mark Brand discovered an integer overflow issue in the swiftshader library.

CVE-2018-6175

Khalil Zhani discovered a URL spoofing issue.

CVE-2018-6176

Jann Horn discovered a way to escalate privileges using extensions.

CVE-2018-6177

Ron Masas discovered an information leak.

CVE-2018-6178

Khalil Zhani discovered a user interface spoofing issue.

CVE-2018-6179

It was discovered that information about files local to the system could be leaked to extensions.

This version also fixes a regression introduced in the previous security update that could prevent decoding of particular audio/video codecs.

For the stable distribution (stretch), these problems have been fixed in version 68.0.3440.75-1~deb9u1.

We recommend that you upgrade your chromium-browser packages.

For the detailed security status of chromium-browser please refer to its security tracker page at: https://security-tracker.debian.org/tracker/chromium-browser

Original Source

Url : http://www.debian.org/security/2018/dsa-4256

CWE : Common Weakness Enumeration

% Id Name
28 % CWE-200 Information Exposure
24 % CWE-787 Out-of-bounds Write (CWE/SANS Top 25)
12 % CWE-20 Improper Input Validation
8 % CWE-704 Incorrect Type Conversion or Cast
8 % CWE-416 Use After Free
4 % CWE-502 Deserialization of Untrusted Data
4 % CWE-434 Unrestricted Upload of File with Dangerous Type (CWE/SANS Top 25)
4 % CWE-362 Race Condition
4 % CWE-190 Integer Overflow or Wraparound (CWE/SANS Top 25)
4 % CWE-125 Out-of-bounds Read

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 263
Application 1
Application 4059
Application 1
Os 167
Os 1
Os 11
Os 6
Os 1
Os 4
Os 1
Os 1
Os 1

Nessus® Vulnerability Scanner

Date Description
2019-01-03 Name : The remote Fedora host is missing a security update.
File : fedora_2018-499f2dbc96.nasl - Type : ACT_GATHER_INFO
2018-09-24 Name : The remote Fedora host is missing a security update.
File : fedora_2018-4a16e37c81.nasl - Type : ACT_GATHER_INFO
2018-08-23 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201808-01.nasl - Type : ACT_GATHER_INFO
2018-08-23 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201808-04.nasl - Type : ACT_GATHER_INFO
2018-07-30 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_b9c525d9919811e8beba080027ef1a23.nasl - Type : ACT_GATHER_INFO
2018-07-27 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-4256.nasl - Type : ACT_GATHER_INFO
2018-07-27 Name : A web browser installed on the remote Windows host is affected by multiple vu...
File : google_chrome_68_0_3440_75.nasl - Type : ACT_GATHER_INFO
2018-07-27 Name : A web browser installed on the remote macOS host is affected by multiple vuln...
File : macosx_google_chrome_68_0_3440_75.nasl - Type : ACT_GATHER_INFO
2018-04-03 Name : An application installed on the remote host is affected by multiple vulnerabi...
File : itunes_12_7_4.nasl - Type : ACT_GATHER_INFO
2018-04-03 Name : An application installed on the remote host is affected by multiple vulnerabi...
File : itunes_12_7_4_banner.nasl - Type : ACT_GATHER_INFO
2018-04-03 Name : A web browser installed on the remote macOS or Mac OS X host is affected by m...
File : macosx_Safari11_1_0.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
Date Informations
2019-10-03 09:24:28
  • Multiple Updates
2019-01-14 21:21:40
  • Multiple Updates
2019-01-10 00:21:32
  • Multiple Updates
2018-12-05 17:21:44
  • Multiple Updates
2018-07-27 09:18:19
  • First insertion