CVE-2018-6156: Heap buffer overflow in WebRTC
A heap buffer overflow flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=841962
External References:
https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html
Other sources
Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
— Launchpad
Incorrect derivation of a packet length in WebRTC caused heap corruption via a crafted video file. This resulted in a potentially exploitable crash.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-6156
- CVE-2019-15903
- CVE-2019-11757
- CVE-2019-25136
- CVE-2020-12412
- CVE-2019-11759
- CVE-2019-11760
- CVE-2019-11761
- CVE-2019-11762
- CVE-2019-11763
- CVE-2019-11765
- CVE-2019-17000
- CVE-2019-17001
- CVE-2019-17002
- CVE-2019-11764
- CVE-2018-6153
- CVE-2018-6154
- CVE-2018-6155
- CVE-2018-6157
- CVE-2018-6158
- CVE-2018-6159
- CVE-2018-6160
- CVE-2018-6161
- CVE-2018-6162
- CVE-2018-6163
- CVE-2018-6164
- CVE-2018-6165
- CVE-2018-6166
- CVE-2018-6167
- CVE-2018-6168
- CVE-2018-6169
- CVE-2018-6170
- CVE-2018-6171
- CVE-2018-6172
- CVE-2018-6173
- CVE-2018-6174
- CVE-2018-6175
- CVE-2018-6176
- CVE-2018-6177
- CVE-2018-6178
- CVE-2018-6179
- CVE-2018-6044
- CVE-2018-4117
- CVE-2018-17460
- CVE-2018-17461
- CVE-2018-6150
- CVE-2018-6151
- CVE-2018-6152
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-6156.
What is the affected software?
The affected software is Mozilla Firefox version up to but excluding 70.
What is the severity of CVE-2018-6156?
The severity of CVE-2018-6156 is high.
How was the vulnerability exploited?
The vulnerability was exploited through incorrect derivation of a packet length in WebRTC via a crafted video file.
Is there a fix available?
Mozilla has released a fix for CVE-2018-6156 in Mozilla Firefox version 70.