| CNNVD-ID编号 | CNNVD-201810-768 | CVE编号 | CVE-2018-17466 |
| 发布时间 | 2018-10-17 | 更新时间 | 2019-04-01 |
| 漏洞类型 | 资料不足 | 漏洞来源 | Quang Nguy?n, Yannic B, Nils, Atte Kettunen,Luyao Liu, James Lee (@Windowsrcer), James Lee of Kryptos Logic and Omair., Lnyas Zhang, Omair, Zhe Jin, Zhen Zhou of NSFOCUS,r,Ned Williamson and Niklas Baumstark, Jun Kokatsu (@shhnjk), Vladimir Metnew, xisigr, Luyao Liu, Samuel Gross, Lin Zuojian, Khalil Zhani |
| 危险等级 | 高危 | 威胁类型 | 远程 |
| 厂商 | |||
Google Chrome是美国谷歌(Google)公司开发的一款Web浏览器。ANGLE(Almost Native Graphics Layer Engine)是一个图形层引擎,它允许Windows用户通过把OpenGL ES 2.0 API转译为DirectX 9或DirectX 11 API调用,来运行WebGL和其他OpenGL ES 2.0内容。
Google Chrome 70.0.3538.67之前版本中的ANGLE存在内存损坏漏洞。远程攻击者可借助特制的HTML页面利用该漏洞在系统上执行任意代码或造成拒绝服务(越界读取内存)。
目前厂商已发布升级了Google Chrome ANGLE 安全漏洞的补丁,Google Chrome ANGLE 安全漏洞的补丁获取链接:
https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2018/12/msg00002.html
来源:UBUNTU
来源:DEBIAN
来源:REDHAT
来源:REDHAT
来源:BID
来源:UBUNTU
来源:BID
来源:REDHAT
来源:REDHAT
来源:REDHAT
来源:MISC
来源:DEBIAN
来源:GENTOO
来源:CONFIRM
链接:https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
来源:DEBIAN
来源:https://www.suse.com/support/update/announcement/2019/suse-su-20190338-1/
链接:链接:无
来源:www.securityfocus.com