CERT-In Vulnerability Note
CIVN-2018-0208
Multiple Vulnerabilities in Google Chrome
Original Issue Date:December 12, 2018
Severity Rating: HIGH
Software Affected
- Google Chrome versions prior to 71.0.3578.80
Overview
Multiple vulnerabilities have been reported in Google Chrome which could be exploited by a remote attacker to execute arbitrary code, gain sensitive information, bypass security restrictions or cause denial-of-service (DoS) conditions on the targeted system.
Description
These vulnerabilities exist in Google Chrome due to heap-based buffer overflow error in Blink, Canvas and Skia, inappropriate implementation error in Extensions, Media, Navigation, Network Authentication and Omnibox, incorrect security UI in Blink, error while validating data in Shell Integration, insufficient policy enforcement in Blink, Navigation, Proxy and URL Formatter, multiple issues in SQLite via WebSQL, out of bounds read error in V8, out of bounds write error in V8, use-after-free error in Blink, MediaRecorder, PDFium, Skia, WebAudio and PDFium. A remote attacker could exploit these vulnerabilities by installing a program on the targeted system.
Successful exploitation of these vulnerabilities could allow the remote attacker to execute arbitrary code, gain sensitive information, bypass security restrictions or cause denial-of-service (DoS) conditions on the targeted system.
Solution
Upgrade to Google Chrome version 71.0.3578.80
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
References
Google Chrome
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html
Security focus
https://www.securityfocus.com/bid/106084/info
CVE Name
CVE-2018-17480
CVE-2018-18342
CVE-2018-17481
CVE-2018-18336
CVE-2018-18335
CVE-2018-18337
CVE-2018-18338
CVE-2018-18339
CVE-2018-18340
CVE-2018-18341
CVE-2018-18343
CVE-2018-18356
CVE-2018-18344
CVE-2018-18345
CVE-2018-18346
CVE-2018-18347
CVE-2018-18348
CVE-2018-18349
CVE-2018-18350
CVE-2018-18351
CVE-2018-18352
CVE-2018-18353
CVE-2018-18354
CVE-2018-18355
CVE-2018-18357
CVE-2018-18358
CVE-2018-18359
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|