RHEL 6 : chromium-browser (RHSA-2018:2282)

critical Nessus Plugin ID 111487

Synopsis

The remote Red Hat host is missing one or more security updates for chromium-browser.

Description

The remote Redhat Enterprise Linux 6 host has a package installed that is affected by multiple vulnerabilities as referenced in the RHSA-2018:2282 advisory.

- chromium-browser: Cross origin information leak in Blink (CVE-2018-4117, CVE-2018-6177)

- chromium-browser: Cross origin information disclosure in Service Workers (CVE-2018-6150)

- chromium-browser: Bad cast in DevTools (CVE-2018-6151)

- chromium-browser: Local file write in DevTools (CVE-2018-6152)

- chromium-browser: Stack buffer overflow in Skia (CVE-2018-6153)

- chromium-browser: Heap buffer overflow in WebGL (CVE-2018-6154, CVE-2018-6162)

- chromium-browser: Use after free in WebRTC (CVE-2018-6155)

- chromium-browser: Heap buffer overflow in WebRTC (CVE-2018-6156)

- chromium-browser: Type confusion in WebRTC (CVE-2018-6157)

- chromium-browser: Use after free in Blink (CVE-2018-6158)

- chromium-browser: Same origin policy bypass in ServiceWorker (CVE-2018-6159, CVE-2018-6164)

- chromium-browser: Same origin policy bypass in WebAudio (CVE-2018-6161)

- chromium-browser: URL spoof in Omnibox (CVE-2018-6163, CVE-2018-6165, CVE-2018-6166, CVE-2018-6167, CVE-2018-6172, CVE-2018-6173, CVE-2018-6175)

- chromium-browser: CORS bypass in Blink (CVE-2018-6168)

- chromium-browser: Permissions bypass in extension installation (CVE-2018-6169)

- chromium-browser: Type confusion in PDFium (CVE-2018-6170)

- chromium-browser: Use after free in WebBluetooth (CVE-2018-6171)

- chromium-browser: Integer overflow in SwiftShader (CVE-2018-6174)

- chromium-browser: Local user privilege escalation in Extensions (CVE-2018-6176)

- chromium-browser: UI spoof in Extensions (CVE-2018-6178)

- chromium-browser: Local file information leak in Extensions (CVE-2018-6179)

- chromium-browser: Request privilege escalation in Extensions (CVE-2018-16064)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL chromium-browser package based on the guidance in RHSA-2018:2282.

See Also

http://www.nessus.org/u?0964608f

https://access.redhat.com/errata/RHSA-2018:2282

https://bugzilla.redhat.com/show_bug.cgi?id=1608186

https://bugzilla.redhat.com/show_bug.cgi?id=1608187

https://bugzilla.redhat.com/show_bug.cgi?id=1608188

https://bugzilla.redhat.com/show_bug.cgi?id=1608189

https://bugzilla.redhat.com/show_bug.cgi?id=1608190

https://bugzilla.redhat.com/show_bug.cgi?id=1608191

https://bugzilla.redhat.com/show_bug.cgi?id=1608192

https://bugzilla.redhat.com/show_bug.cgi?id=1608193

https://bugzilla.redhat.com/show_bug.cgi?id=1608194

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=1608177

https://bugzilla.redhat.com/show_bug.cgi?id=1608178

https://bugzilla.redhat.com/show_bug.cgi?id=1608179

https://bugzilla.redhat.com/show_bug.cgi?id=1608180

https://bugzilla.redhat.com/show_bug.cgi?id=1608181

https://bugzilla.redhat.com/show_bug.cgi?id=1608182

https://bugzilla.redhat.com/show_bug.cgi?id=1608183

https://bugzilla.redhat.com/show_bug.cgi?id=1608185

https://bugzilla.redhat.com/show_bug.cgi?id=1608195

https://bugzilla.redhat.com/show_bug.cgi?id=1608196

https://bugzilla.redhat.com/show_bug.cgi?id=1608197

https://bugzilla.redhat.com/show_bug.cgi?id=1608198

https://bugzilla.redhat.com/show_bug.cgi?id=1608199

https://bugzilla.redhat.com/show_bug.cgi?id=1608200

https://bugzilla.redhat.com/show_bug.cgi?id=1608201

https://bugzilla.redhat.com/show_bug.cgi?id=1608202

https://bugzilla.redhat.com/show_bug.cgi?id=1608203

https://bugzilla.redhat.com/show_bug.cgi?id=1608204

https://bugzilla.redhat.com/show_bug.cgi?id=1608205

https://bugzilla.redhat.com/show_bug.cgi?id=1608206

https://bugzilla.redhat.com/show_bug.cgi?id=1608207

https://bugzilla.redhat.com/show_bug.cgi?id=1608208

Plugin Details

Severity: Critical

ID: 111487

File Name: redhat-RHSA-2018-2282.nasl

Version: 1.11

Type: local

Agent: unix

Published: 8/2/2018

Updated: 4/27/2024

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2018-6174

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2018-6152

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:chromium-browser, cpe:/o:redhat:enterprise_linux:6

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 7/30/2018

Vulnerability Publication Date: 4/3/2018

Reference Information

CVE: CVE-2018-16064, CVE-2018-4117, CVE-2018-6150, CVE-2018-6151, CVE-2018-6152, CVE-2018-6153, CVE-2018-6154, CVE-2018-6155, CVE-2018-6156, CVE-2018-6157, CVE-2018-6158, CVE-2018-6159, CVE-2018-6161, CVE-2018-6162, CVE-2018-6163, CVE-2018-6164, CVE-2018-6165, CVE-2018-6166, CVE-2018-6167, CVE-2018-6168, CVE-2018-6169, CVE-2018-6170, CVE-2018-6171, CVE-2018-6172, CVE-2018-6173, CVE-2018-6174, CVE-2018-6175, CVE-2018-6176, CVE-2018-6177, CVE-2018-6178, CVE-2018-6179

RHSA: 2018:2282