ALT-BU-2018-3227-1
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2019-04478
Уязвимость реализации механизма CORS браузера Google Chrome, позволяющая нарушителю раскрыть защищаемую информацию
BDU:2019-04480
Уязвимость реализации бэкэнда Page.downloadBehavior браузера Google Chrome, позволяющая нарушителю убедить пользователя установить вредоносное расширение
Modified: 2024-11-21
CVE-2018-6084
Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker to execute arbitrary code via an executable file.
Modified: 2024-11-21
CVE-2018-6085
Re-entry of a destructor in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/826626
- https://crbug.com/826626
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6086
A double-eviction in the Incognito mode cache that lead to a user-after-free in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/827492
- https://crbug.com/827492
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6087
A use-after-free in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/813876
- https://crbug.com/813876
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6088
An iterator-invalidation bug in PDFium in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/822091
- https://crbug.com/822091
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6089
A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/808838
- https://crbug.com/808838
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6090
An integer overflow that lead to a heap buffer-overflow in Skia in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/820913
- https://crbug.com/820913
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6091
Service Workers can intercept any request made by an
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/771933
- https://crbug.com/771933
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6092
An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/819869
- https://crbug.com/819869
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
- 44860
- 44860
Modified: 2024-11-21
CVE-2018-6093
Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/780435
- https://crbug.com/780435
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6094
Inline metadata in GarbageCollection in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/633030
- https://crbug.com/633030
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6095
Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local files via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/637098
- https://crbug.com/637098
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6096
A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/776418
- https://crbug.com/776418
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6097
Incorrect handling of asynchronous methods in Fullscreen in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to enter full screen without showing a warning via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/806162
- https://crbug.com/806162
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6098
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/798892
- https://crbug.com/798892
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6099
A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/808825
- https://crbug.com/808825
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6100
Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/811117
- https://crbug.com/811117
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6101
A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if the user is running a remote DevTools debugging server.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/813540
- https://crbug.com/813540
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6102
Missing confusable characters in Internationalization in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/813814
- https://crbug.com/813814
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6103
A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass permission policy via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/816033
- https://crbug.com/816033
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6104
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/820068
- https://crbug.com/820068
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6105
Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/803571
- https://crbug.com/803571
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6106
An asynchronous generator may return an incorrect state in V8 in Google Chrome prior to 66.0.3359.117 allowing a remote attacker to potentially exploit object corruption via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/805729
- https://crbug.com/805729
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6107
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/808316
- https://crbug.com/808316
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6108
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/816769
- https://crbug.com/816769
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6109
readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/710190
- https://crbug.com/710190
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6110
Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a local non-HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/777737
- https://crbug.com/777737
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6111
An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359.117 allowed a local attacker to execute arbitrary code via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/780694
- https://crbug.com/780694
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6112
Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/798096
- https://crbug.com/798096
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6113
Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/805900
- https://crbug.com/805900
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6114
Incorrect enforcement of CSP for
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/811691
- https://crbug.com/811691
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6115
Inappropriate setting of the SEE_MASK_FLAG_NO_UI flag in file downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially bypass OS malware checks via a crafted HTML page.
Modified: 2024-11-21
CVE-2018-6116
A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/822266
- https://crbug.com/822266
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6117
Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- 103917
- 103917
- RHSA-2018:1195
- RHSA-2018:1195
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/822465
- https://crbug.com/822465
- GLSA-201804-22
- GLSA-201804-22
- DSA-4182
- DSA-4182
Modified: 2024-11-21
CVE-2018-6150
Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Modified: 2024-11-21
CVE-2018-6152
The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page and user interaction.
- 104887
- 104887
- RHSA-2018:2282
- RHSA-2018:2282
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.html
- https://crbug.com/805445
- https://crbug.com/805445
- GLSA-201808-01
- GLSA-201808-01
- DSA-4256
- DSA-4256
Closed bugs
Не работает вкладка
Package make-initrd updated to version 2.0.8-alt1 for branch sisyphus in task 205420.
Closed bugs
Добавить конфликт на kinit-utils < 1.5.25-alt5
make-initrd не помещает модули crc32c в initrd