Vulnerability CVE-2018-17463: Information

Description

Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

Severity: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: Nov. 14, 2018
Modified: Aug. 24, 2020

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://crbug.com/888923
  • Permissions Required
  • Vendor Advisory
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
  • Release Notes
  • Vendor Advisory
DSA-4330
  • Third Party Advisory
RHSA-2018:3004
  • Third Party Advisory
105666
  • Third Party Advisory
  • VDB Entry
GLSA-201811-10
  • Third Party Advisory
http://packetstormsecurity.com/files/156640/Google-Chrome-67-68-69-Object.create-Type-Confusion.html
      1. Configuration 1

        cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
        End excliding
        70.0.3538.67

        Configuration 2

        cpe:2.3:o:redhat:linux_desktop:6.0:*:*:*:*:*:*:*

        cpe:2.3:o:redhat:linux_workstation:6.0:*:*:*:*:*:*:*

        cpe:2.3:o:redhat:linux_server:6.0:*:*:*:*:*:*:*

        Configuration 3

        cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*