Name | CVE-2018-18343 |
Description | Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-4352-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
chromium (PTS) | stretch (security), stretch (lts), stretch | 73.0.3683.75-1~deb9u1 | fixed |
buster, buster (security) | 90.0.4430.212-1~deb10u1 | fixed | |
bullseye (security), bullseye | 120.0.6099.224-1~deb11u1 | fixed | |
bookworm | 121.0.6167.139-1~deb12u1 | fixed | |
bookworm (security) | 124.0.6367.60-1~deb12u1 | fixed | |
trixie | 123.0.6312.105-1~deb13u1 | fixed | |
sid | 124.0.6367.78-1 | fixed | |
chromium-browser (PTS) | stretch (security), stretch (lts), stretch | 71.0.3578.80-1~deb9u1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
chromium | source | (unstable) | 71.0.3578.80-1 | |||
chromium-browser | source | stretch | 71.0.3578.80-1~deb9u1 | DSA-4352-1 |