An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-firefox-esr | Mar 28, 2019 | Dec 11, 2018 | |
| Arch Linux | View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗ | arch-linux-upgrade-latest | Jul 11, 2025 | Dec 11, 2018 |
| Centos_linux | — | centos-upgrade-chromium-browsercentos-upgrade-chromium-browser-debuginfocentos-upgrade-firefoxcentos-upgrade-firefox-debuginfocentos-upgrade-thunderbirdcentos-upgrade-thunderbird-debuginfocentos-upgrade-thunderbird-debugsource | Feb 22, 2019 | Dec 7, 2018 |
| Debian | debian-upgrade-chromiumdebian-upgrade-firefox-esrdebian-upgrade-thunderbird | Dec 9, 2018 | Dec 7, 2018 | |
| Freebsd | freebsd-upgrade-package-firefoxfreebsd-upgrade-package-firefox-esrfreebsd-upgrade-package-thunderbirdfreebsd-upgrade-package-chromium | Feb 13, 2019 | Feb 13, 2019 | |
| Gentoo Linux | gentoo-linux-upgrade-mail-client-thunderbirdgentoo-linux-upgrade-mail-client-thunderbird-bingentoo-linux-upgrade-www-client-chromiumgentoo-linux-upgrade-www-client-firefoxgentoo-linux-upgrade-www-client-firefox-bingentoo-linux-upgrade-www-client-google-chrome | Mar 11, 2019 | Dec 11, 2018 | |
| Google Chrome | google-chrome-upgrade-latest | Dec 21, 2018 | Dec 11, 2018 | |
| Mfsa2019 04 | mozilla-firefox-upgrade-65_0_1 | Feb 13, 2019 | Dec 11, 2018 | |
| Mfsa2019 05 | mozilla-firefox-esr-upgrade-60_5_1 | Feb 13, 2019 | Dec 11, 2018 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-60_5_1 | Feb 15, 2019 | Dec 11, 2018 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-mail-thunderbird-60-6-1-11-4-9-0-1-2-0oracle-solaris-11-4-upgrade-mail-thunderbird-plugin-thunderbird-lightning-60-6-1-11-4-9-0-1-2-0oracle-solaris-11-4-upgrade-web-browser-firefox-60-5-1-11-4-7-0-1-3-0oracle-solaris-11-4-upgrade-web-data-firefox-bookmarks-60-5-1-11-4-7-0-1-3-0 | Mar 20, 2019 | Dec 11, 2018 | |
| Oracle_linux | — | oracle-linux-upgrade-firefox | Feb 20, 2019 | Dec 4, 2018 |
| Redhat_linux | redhat-upgrade-thunderbirdredhat-upgrade-thunderbird-debuginforedhat-upgrade-thunderbird-debugsource | Dec 11, 2018 | Dec 10, 2018 | |
| Suse | — | suse-upgrade-chromedriversuse-upgrade-chromiumsuse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-buildsymbolssuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-othersuse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-buildsymbolssuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Dec 9, 2018 | Dec 7, 2018 |
| Ubuntu | ubuntu-upgrade-firefoxubuntu-upgrade-thunderbird | Mar 7, 2019 | Dec 7, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub