CERT-In Advisory
CIAD-2018-0022
Multiple Vulnerabilities in Google Chrome
Original Issue Date: September 11, 2018
Severity Rating: High
Software Affected
- Google Chrome versions prior to 69.0.3497.81
Overview
Multiple vulnerabilities have been reported in Google Chrome, which could be exploited by a remote attacker to execute arbitrary code, obtain sensitive information, bypass security restrictions or cause denial-of-service conditions on a targeted system.
Description
These vulnerabilities exist in Google Chrome due to out-of-bounds memory read and write errors, use-after-free error, integer and buffer overflow errors, security feature bypass, data leak, local file access and URL spoof errors.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code in the context of the browser, obtain sensitive information, bypass security restrictions and cause denial-of-service conditions on a targeted system.
Solution
Upgrade to Google chrome version 69.0.3497.81 as mentioned at:
https://chromereleases.googleblog.com/2018/09/stable-channel-update-for-desktop.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2018/09/stable-channel-update-for-desktop.html
References
Security Focus
https://www.securityfocus.com/bid/105215
CVE Name
CVE-2018-16065
CVE-2018-16066
CVE-2018-16067
CVE-2018-16068
CVE-2018-16069
CVE-2018-16070
CVE-2018-16071
CVE-2018-16072
CVE-2018-16073
CVE-2018-16074
CVE-2018-16075
CVE-2018-16076
CVE-2018-16077
CVE-2018-16078
CVE-2018-16079
CVE-2018-16080
CVE-2018-16081
CVE-2018-16082
CVE-2018-16083
CVE-2018-16084
CVE-2018-16085
CVE-2018-16086
CVE-2018-16087
CVE-2018-16088
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|